SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel. You have been asked to configure automated responses to security incidents. Which TWO of the following can be used to automate responses in Microsoft Sentinel?
⚠ Common exam trap
Candidates often confuse 'automation' with 'visualization' or 'integration', incorrectly selecting Workbooks (which only display data) or Custom connectors (which are infrastructure for APIs, not response actions) instead of recognizing that only Playbooks and Automation rules directly execute automated responses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Playbooks (Azure Logic Apps)
Playbooks in Microsoft Sentinel are built on Azure Logic Apps, allowing you to automate complex, multi-step response workflows triggered by security incidents. They can execute actions like blocking IPs, resetting passwords, or enriching alerts with threat intelligence, making them a core automation tool for incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Workbooks
Why it's wrong here
Workbooks in Microsoft Sentinel are interactive dashboards built from Azure Monitor Workbooks. They aggregate and visualize security data from KQL queries, providing situational awareness and reporting, but they are read-only renderers. A workbook cannot execute an automatic response, modify an incident, or invoke a playbook; it simply presents data to analysts, so it fails the requirement for automated remediation.
- ✗
Power Automate flows
Why it's wrong here
While Power Automate shares the same underlying workflow engine as Azure Logic Apps, Microsoft Sentinel does not expose a native Power Automate trigger for incident creation or updates. Sentinel's automation model is built on Logic Apps playbooks, which use the Sentinel connector with security-specific actions; Power Automate flows are geared toward business productivity scenarios and lack the deep integration and incident schema support required for security orchestration. Relying on Power Automate would require unsupported workarounds and is not a valid answer for incident automation.
- ✓
Playbooks (Azure Logic Apps)
Why this is correct
Playbooks are cloud workflows built on Azure Logic Apps that you can invoke from Microsoft Sentinel to automate a security response. They can be triggered by an analytics rule (automatically on alert creation) or by an automation rule on an incident, and they support actions such as isolating a compromised host, resetting credentials, opening a ticket, or sending a Teams notification. Because they run with the Sentinel connector's context, playbooks are the native mechanism for incident-triggered orchestration and satisfy the requirement for automated responses.
- ✗
Custom connectors
Why it's wrong here
Custom connectors are used to extend Azure Logic Apps (and Power Apps) to call external REST APIs that are not among the built-in connectors. They are not a standalone automation feature in Microsoft Sentinel; rather, they provide authentication and API schema definitions for playbooks to interact with third-party services. A custom connector by itself cannot receive an incident trigger, evaluate conditions, or run actions, so selecting it would conflate a connectivity building block with an orchestration engine.
- ✓
Automation rules
Why this is correct
Automation rules in Microsoft Sentinel allow incident-triggered responses without requiring a separate Logic App, directly satisfying the requirement for automated responses to security incidents. They can run playbooks, change incident status, assign ownership, or add tags based on conditions such as severity or entity type, all natively within the Sentinel workspace. This meets the stem’s constraint of configuring automated responses without external orchestration dependencies.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.