SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel. You receive an alert for a suspicious sign-in from an unusual location. You want to automatically create an incident and assign it to the security team for investigation. What should you configure?
⚠ Common exam trap
Candidates often think a playbook is required for incident creation, but automation rules provide a simpler, native mechanism that can both create incidents and assign ownership without custom code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an automation rule that runs when the alert is generated, creates an incident, and sets the owner to the security team.
Automation rules in Microsoft Sentinel allow you to automatically create incidents from alerts and assign them to specific teams or owners. This is the native, efficient method to handle the scenario without manual intervention or custom playbooks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the user to a watchlist and configure a fusion rule.
Why it's wrong here
Watchlists are user-defined tables of data used for enrichment, correlation, and filtering in analytics rules—they do not create incidents when users are added. Fusion rules apply machine learning to combine multiple alerts and related signals into a single incident, but they cannot be configured to act on a simple watchlist assignment. Therefore, adding the user to a watchlist and configuring Fusion would not generate an incident or assign it to the security team.
- ✗
Create a playbook that triggers on the alert and creates an incident manually.
Why it's wrong here
Playbooks are Azure Logic Apps-based workflows that run automated response actions such as sending emails, resetting credentials, or blocking network traffic after an alert or incident is generated. They lack native capability to create an incident record; incident creation is reserved for analytics rules and automation rules. Attempting to create an incident manually within a playbook is unsupported and bypasses Sentinel's designed orchestration flow.
- ✗
Modify the analytics rule to set the incident creation setting to 'Create incident from alert'.
Why it's wrong here
The analytics rule's 'Create incident from alert' setting is a binary toggle that controls whether Sentinel generates an incident for each alert the rule triggers. While enabling this toggle will produce an incident, it does not assign an owner or perform any other triage actions, so the security team would not be automatically designated. In the given scenario, an automation rule is the appropriate place to both create the incident and set the owner, because it can chain multiple actions on alert creation.
- ✓
Configure an automation rule that runs when the alert is generated, creates an incident, and sets the owner to the security team.
Why this is correct
Automation rules are Sentinel's native orchestration mechanism that can trigger on alert creation and perform actions such as creating an incident, assigning an owner, changing severity, and running playbooks. By configuring a rule that runs when the alert is generated, you ensure the incident is created with the security team as the owner in one atomic step. This approach centralizes lifecycle management and is recommended over manual playbook or analytics-rule-only configurations for consistent ownership.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.