Courseiva

SC-200 Automation rule Practice Question

Your organization uses Microsoft Sentinel. You need to create an incident response playbook that automatically isolates a compromised device when a high-severity incident is created. The playbook should only run during business hours (9 AM - 5 PM local time). How should you configure this?

⚠ Common exam trap

It's easy for candidates to assume automation rules can filter by time of day, similar to conditions on other incident fields. However, automation rules cannot evaluate temporal conditions like 'created between 9 AM and 5 PM'. The correct approach is to embed a time condition directly in the playbook logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a condition in the playbook to check the current time

Microsoft Sentinel automation rules cannot evaluate conditions based on the time of day (e.g., creation hour). The appropriate method is to add a condition in the playbook itself (Azure Logic Apps) to check the current time and proceed only during business hours. This approach gives you full control over the playbook's execution schedule without relying on unsupported automation rule conditions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the analytics rule to only create incidents during business hours

    Why it's wrong here

    Suppressing incident creation during off-hours also suppresses detection and triage, so the SOC never sees the compromise; the playbook trigger is the incident, not the clock. Analytics rule scheduling controls when queries run, which is useful for reducing noise on low-fidelity rules, not for gating a response playbook's execution window.

  • ✓

    Add a condition in the playbook to check the current time

    Why this is correct

    A time-based condition inside the playbook logic evaluates the current time before triggering isolation, satisfying the business-hours constraint. However, Microsoft Sentinel playbooks are Logic Apps, so this check must use a built-in date/time expression or condition action, and the recurrence trigger still fires around the clock.

  • ✗

    Use a workbook to schedule the playbook

    Why it's wrong here

    Workbooks are read-only dashboards for visualising Sentinel data; they hold no scheduling or execution capability and cannot invoke a playbook. Workbooks are the right choice for reporting on incident trends or hunting results, not for time-gated automated response actions.

  • ✗

    Create an automation rule with a condition on the incident creation time

    Why it's wrong here

    Automation rules trigger on incident creation and can run playbooks, but their conditions cannot evaluate the wall-clock time of creation, so a 9-5 window cannot be expressed. Automation rules suit owner, severity, and entity-based triage actions; time-of-day gating belongs inside the playbook's Logic App recurrence or condition.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.