Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel. You need to automatically assign incidents to the appropriate SOC tier based on severity. What should you create?

⚠ Common exam trap

Test-takers frequently confuse automation rules with playbooks, assuming that any automated response requires a playbook, when in fact simple owner assignment is a native automation rule action that does not need a separate playbook or Power Automate workflow.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An automation rule with an owner assignment action

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific owners based on conditions like severity, using the 'Assign owner' action. This directly meets the requirement to route incidents to the appropriate SOC tier without manual intervention, leveraging Sentinel's native incident management capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A data connector to Microsoft Teams

    Why it's wrong here

    A Microsoft Teams data connector only ingests Teams audit and activity logs into Microsoft Sentinel for detection and hunting. It cannot assign incident owners. Automation rules perform severity-based owner assignment. Teams connectors suit monitoring collaboration activity, such as suspicious file sharing or meeting anomalies.

  • ✗

    A scheduled analytics rule

    Why it's wrong here

    Scheduled analytics rules generate alerts and incidents on a query schedule; they contain no owner-assignment logic. Automation rules, triggered on incident creation, set owner based on severity. Scheduled rules suit recurring detection queries, such as hourly sign-in anomaly scans, not tier routing.

  • ✗

    A playbook in Microsoft Power Automate

    Why it's wrong here

    A playbook in Microsoft Power Automate is incorrect because Microsoft Sentinel playbooks are built on Azure Logic Apps, not Power Automate, to natively automate incident responses and assignments within Sentinel. While Power Automate can automate workflows and integrate with many services, it is not the native mechanism for Sentinel's incident automation. It would be a suitable choice for general business process automation, potentially triggered by Sentinel, but not for direct incident tier assignment within the platform's incident management system.

  • ✓

    An automation rule with an owner assignment action

    Why this is correct

    Automation rules in Microsoft Sentinel trigger on incident creation and can execute an owner assignment action, setting the incident's owner to the relevant SOC tier. This directly satisfies the requirement to assign incidents automatically based on severity, using the severity condition within the rule's trigger criteria.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.