SC-200 Manage a security operations environment Practice Question
Your security team uses Microsoft Sentinel automation rules to respond to incidents. You need to ensure that critical incidents are automatically assigned to a senior analyst in the Americas time zone and that a Teams message is sent to a specific channel. Which configuration should you use?
⚠ Common exam trap
Many exam-takers confuse the capabilities of analytics rules versus automation rules, thinking that analytics rules can directly execute playbooks or set owners, when in fact automation rules are the correct mechanism for triggering playbooks and modifying incident properties after creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a playbook that assigns the incident and sends a Teams message, then attach it to a automation rule
Automation rules in Microsoft Sentinel can trigger a playbook when an incident is created or updated. By creating a playbook that assigns the incident to a specific senior analyst (using Microsoft Entra ID or a watchlist for mapping) and sends a Teams message via the Teams connector, then attaching that playbook to an automation rule with conditions for critical severity, you meet both requirements. This approach leverages native Sentinel automation without custom connectors or manual email triggers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a watchlist to map critical incidents to senior analysts and trigger an email
Why it's wrong here
Watchlists are static CSV-like data sets in Microsoft Sentinel used for lookups, correlation, and enrichment; they have no native capability to assign incident owners or trigger email actions. Mapping critical incidents to senior analysts via a watchlist would only provide a lookup table that a playbook must reference, and the actual assignment and email actions would still require a playbook attached to an automation rule. Since watchlists do not execute automated actions themselves, this option cannot fulfill the requirement.
- ✗
Configure the analytics rule to set the incident owner and add a playbook action
Why it's wrong here
Analytics rules in Microsoft Sentinel process data, detect threats, and generate alerts; they do not create incidents directly, and they have no incident owner property or playbook action setting. Incident ownership is assigned at the incident level after the incident is created, typically through a playbook invoked by an automation rule or manually. Configuring the analytics rule to set an owner or add a playbook action is technically unsupported because automation rules, not analytics rules, attach playbooks to incidents.
- ✗
Create a custom connector in Power Automate to monitor Sentinel incidents
Why it's wrong here
Power Automate has built-in Microsoft Sentinel connectors, such as 'When a response to a Microsoft Sentinel alert is triggered' and 'When an incident is created or updated,' so a custom connector is unnecessary. Even if you built a custom connector to monitor Sentinel incidents, it would only observe incidents; it would not automatically assign ownership or send a Teams message without additional logic. The supported pattern is to create a playbook with the required actions and attach it to an automation rule, not to build a custom connector.
- ✓
Create a playbook that assigns the incident and sends a Teams message, then attach it to a automation rule
Why this is correct
A playbook in Microsoft Sentinel is an Azure Logic Apps workflow that can perform actions such as updating the incident owner and sending a Teams message. By attaching this playbook to an automation rule, the rule triggers the playbook when incidents meet specific conditions (e.g., creation, severity, or status change), automating the assignment and notification. This is the correct approach because automation rules are designed to run playbooks as incident-triggered actions, and the playbook can use the 'Update incident' action to set the owner.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.