SC-200 Manage a security operations environment Practice Question
Your SOC team uses Microsoft Sentinel and Microsoft Defender XDR. You have configured automated responses using playbooks. However, some playbooks fail to execute when triggered from Microsoft Defender XDR incidents. You need to ensure that the playbooks run successfully. What should you verify?
⚠ Common exam trap
A common mix-up: candidates assume playbook failures are due to permissions or resource location, but the SC-200 exam specifically tests the understanding that automation rules require the correct 'incident provider' filter to match incidents from Microsoft Defender XDR.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure that the automation rule that triggers the playbook has the correct 'incident provider' set to 'Microsoft Defender XDR'.
Microsoft Defender XDR incidents that are synchronized to Microsoft Sentinel include an 'incident provider' property. Automation rules in Sentinel must have the 'incident provider' set to 'Microsoft Defender XDR' to trigger playbooks specifically for those incidents. If this property is not configured correctly, the automation rule will not match the incoming incidents, causing the playbook to fail to execute.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Confirm that the playbook is stored in the same resource group as Microsoft Sentinel.
Why it's wrong here
Playbooks are Azure Logic Apps that can be deployed to any resource group independently of the Microsoft Sentinel workspace. The automation rule references the playbook by its resource ID, and Sentinel can invoke Logic Apps across resource groups provided the appropriate managed identity or service principal has permissions to trigger the playbook. The resource group location or name has no bearing on whether the automation rule fires for Defender XDR incidents, so this check would not resolve the issue.
- ✗
Verify that the playbook is connected to Microsoft Teams for approval.
Why it's wrong here
Connecting the playbook to Microsoft Teams is an optional action you might include inside the Logic App for manual approval, but it is not a prerequisite for Sentinel's automation to invoke the playbook. An automation rule triggers a playbook via an API call; if the rule has the wrong incident provider filter, the rule never runs regardless of Teams connectivity. Removing Teams integration would not change whether the rule matches the incident source, so verifying Teams is irrelevant here.
- ✓
Ensure that the automation rule that triggers the playbook has the correct 'incident provider' set to 'Microsoft Defender XDR'.
Why this is correct
The 'incident provider' condition in an automation rule filters which incidents can trigger the playbook. Incidents created from Microsoft Defender XDR alerts have their provider set to 'Microsoft Defender XDR', so the rule must explicitly include this provider in its condition; otherwise, the rule will silently skip those incidents. This setting is the most likely cause when Defender XDR incidents do not trigger the playbook while other incident providers, such as 'Azure Security Center' or 'Microsoft Sentinel', still work.
- ✗
Check that the service principal has global administrator role in Microsoft Entra ID.
Why it's wrong here
A service principal requires only the minimal permissions to invoke the Logic App, typically the 'Microsoft Sentinel Responder' role on the resource group or a custom role with Microsoft.Logic/workflows/triggers/run/action. Assigning global administrator in Microsoft Entra ID grants excessive, unnecessary privileges and would not make the automation rule more likely to trigger. The rule's trigger behavior is governed by its own conditions and the playbook's access control, not by the Entra ID directory role of a service principal, so this check addresses the wrong layer.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.