SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel. You need to ensure that incident response times are monitored and reported. Which TWO capabilities should you use?
⚠ Common exam trap
Candidates often confuse playbooks (automated response actions) with automation rules (incident orchestration) and overlook workbooks in favor of UEBA or watchlists, which are unrelated to monitoring response times.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automation rules
Automation rules (C) are correct because they allow you to define conditions and actions that automatically trigger when an incident is created or updated, enabling consistent assignment, severity changes, and tagging. Workbooks (E) are correct because they provide customizable visualizations and reports that can track key metrics like incident response times, mean time to acknowledge (MTTA), and mean time to remediate (MTTR) using KQL queries against Sentinel's security data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Playbooks
Why it's wrong here
Playbooks in Microsoft Sentinel are automated workflows built on Azure Logic Apps, triggered by alerts or incidents to perform response actions like isolating a machine or sending a notification. However, they are not a monitoring or reporting feature; they lack built-in capabilities to track or visualize response times, so unless you manually code telemetry capture within the playbook logic, you cannot ensure SLA compliance using playbooks alone.
- ✗
UEBA
Why it's wrong here
UEBA (User and Entity Behavior Analytics) in Sentinel uses machine learning to profile normal behavior for users and entities, detecting anomalies and producing risk scores for investigation. It focuses on identifying and prioritizing security threats, not on capturing operational metrics such as the elapsed time between incident creation and first response. Because the requirement is to ensure a service-level target is met, UEBA does not provide the necessary timeline calculations or dashboards.
- ✓
Automation rules
Why this is correct
Automation rules in Sentinel are the correct choice because they let you define conditions and run actions when an incident is created or updated, including updating fields and setting tags. By configuring a rule that stamps the incident's 'Created' time and another that records when the incident transitions to 'In Progress' or is assigned, you can capture the exact response start time. This information is stored in the incident's properties and can later be queried to compute time-to-respond, directly enabling monitoring of response times.
- ✗
Watchlists
Why it's wrong here
Watchlists are table-like collections of reference data that you upload as CSV files, used to enrich and correlate queries during investigations, such as matching IP addresses or account names. They are not designed to store time-series operational data or incident lifecycle timestamps, and they provide no built-in mechanism to track when events occur. Thus, watchlists cannot help you measure or ensure incident response times meet SLAs.
- ✓
Workbooks
Why this is correct
Workbooks are interactive dashboards that run KQL queries against Log Analytics data, allowing you to render charts, grids, and tiles. They can display response-time metrics (e.g., average time to respond, breached incidents) by querying the SecurityIncident table or custom logs that contain the necessary timestamps. However, workbooks only visualize data that already exists; to actually 'ensure' monitoring, you must first collect the timestamps via automation rules or other means, making workbooks a complementary but not sole solution.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.