Courseiva

SC-200 Manage a security operations environment Practice Question

Your SOC team needs to ensure that all incidents in Microsoft Sentinel are assigned to an analyst within 30 minutes of creation. Which TWO configurations should you implement?

⚠ Common exam trap

Many exam-takers confuse notification actions (email, Teams) with assignment actions, assuming that notifying a manager or posting to a channel fulfills the requirement to 'assign' the incident, but only setting the owner field in the incident object actually assigns it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a playbook that uses the Update Incident action to set the owner field.

A playbook (an Azure Logic Apps workflow) can use the 'Update Incident' action to programmatically set the owner field on an incident. This allows you to implement custom assignment logic, such as round-robin or based on analyst skill set, triggered by an automation rule or manually. Option C is correct because an automation rule can directly set the owner field when an incident is created, without needing a playbook, by using the 'Update incident' action within the rule itself. Both configurations ensure incidents are assigned within the required 30-minute window.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a playbook that uses the Update Incident action to set the owner field.

    Why this is correct

    Microsoft Sentinel playbooks, built on Azure Logic Apps, include an 'Update Incident' action that can directly set the incident's Owner property to a specific user or group. When invoked from an automation rule on incident creation, this action assigns ownership as part of the incident lifecycle, making it a fully valid solution. The playbook can also incorporate conditions or lookups to choose the right owner dynamically.

  • ✗

    Set up a playbook that sends an email to the SOC manager when an incident is created.

    Why it's wrong here

    This approach only sends an email notification to the SOC manager; it does not modify any property of the incident record. Sending an email does not invoke the 'Update Incident' action, so the Owner field remains unassigned and the incident is not automatically routed to an analyst. While notifications are useful for awareness, they fail to meet the requirement of assigning an owner to every incident.

  • ✓

    Create an automation rule that triggers when an incident is created and sets the owner.

    Why this is correct

    Automation rules in Microsoft Sentinel run immediately when an incident is created and can perform an 'Assign owner' action directly, setting the Owner field without requiring a Logic Apps playbook. This is the recommended lightweight approach for simple, consistent assignment of all new incidents to a specific user or group. The rule evaluates conditions and applies the owner based on the configured settings.

  • ✗

    Configure a Microsoft Teams connector to post incidents to a channel.

    Why it's wrong here

    Posting incidents to a Microsoft Teams channel creates a collaboration message but does not update the underlying incident data in Sentinel. The Teams connector merely sends a notification with incident details; it has no capability to set the Owner field or otherwise change the incident's assignment. This action would only inform team members, not satisfy the requirement for automatic owner assignment.

  • ✗

    Modify the analytics rule to include a custom details field for analyst name.

    Why it's wrong here

    Custom details in an analytics rule extract specific data fields from the query results and add them to the incident, but they are read-only information stored on the incident. Adding an 'analyst name' custom detail does not trigger any assignment logic, so the Owner field remains empty. This is a data-enrichment mechanism, not an ownership assignment mechanism.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.