SC-200 Automation rule Practice Question
Your organization uses Microsoft Sentinel. You need to create an incident response playbook that automatically isolates a compromised device when a high-severity incident is created. The playbook should only run during business hours (9 AM - 5 PM local time). How should you configure this?
⚠ Common exam trap
It's easy for candidates to assume automation rules can filter by time of day, similar to conditions on other incident fields. However, automation rules cannot evaluate temporal conditions like 'created between 9 AM and 5 PM'. The correct approach is to embed a time condition directly in the playbook logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a condition in the playbook to check the current time
Microsoft Sentinel automation rules cannot evaluate conditions based on the time of day (e.g., creation hour). The appropriate method is to add a condition in the playbook itself (Azure Logic Apps) to check the current time and proceed only during business hours. This approach gives you full control over the playbook's execution schedule without relying on unsupported automation rule conditions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the analytics rule to only create incidents during business hours
Why it's wrong here
Suppressing incident creation during off-hours also suppresses detection and triage, so the SOC never sees the compromise; the playbook trigger is the incident, not the clock. Analytics rule scheduling controls when queries run, which is useful for reducing noise on low-fidelity rules, not for gating a response playbook's execution window.
- ✓
Add a condition in the playbook to check the current time
Why this is correct
A time-based condition inside the playbook logic evaluates the current time before triggering isolation, satisfying the business-hours constraint. However, Microsoft Sentinel playbooks are Logic Apps, so this check must use a built-in date/time expression or condition action, and the recurrence trigger still fires around the clock.
- ✗
Use a workbook to schedule the playbook
Why it's wrong here
Workbooks are read-only dashboards for visualising Sentinel data; they hold no scheduling or execution capability and cannot invoke a playbook. Workbooks are the right choice for reporting on incident trends or hunting results, not for time-gated automated response actions.
- ✗
Create an automation rule with a condition on the incident creation time
Why it's wrong here
Automation rules trigger on incident creation and can run playbooks, but their conditions cannot evaluate the wall-clock time of creation, so a 9-5 window cannot be expressed. Automation rules suit owner, severity, and entity-based triage actions; time-of-day gating belongs inside the playbook's Logic App recurrence or condition.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.