Courseiva

SC-200 Manage a security operations environment Practice Question

Your SOC team uses Microsoft Sentinel to manage incidents. You want to categorize incidents based on the MITRE ATT&CK technique. You notice that some incidents are not being tagged with the correct technique. What should you check first?

⚠ Common exam trap

SC-200 often tests the assumption that automation (playbooks or automation rules) can rewrite incident metadata like MITRE technique tags, when in fact the analytics rule is the authoritative source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The analytics rule that generated the incident has the correct MITRE ATT&CK technique selected.

MITRE ATT&CK technique tags on a Microsoft Sentinel incident are inherited directly from the analytics (detection) rule that generated the incident. If the rule was created without the correct technique mapped — or the mapping was later edited — every incident it produces will carry the wrong or missing tag. The first place to verify is therefore the analytics rule's 'Incident settings' / 'MITRE ATT&CK' mapping, not downstream automation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The playbook assigned to the incident is overriding the technique tag.

    Why it's wrong here

    Playbooks run after an incident is created and act on its existing properties; they do not set or overwrite the MITRE ATT&CK technique mapping. Analytics rules assign techniques at creation time. Playbooks are the right tool for automated response actions, such as isolating a host or posting to Teams.

  • ✗

    The incident creation rule in the automation section is misconfigured.

    Why it's wrong here

    Sentinel's Automation section holds playbook rules and automation rules that trigger responses; it contains no incident creation rules, which live under Analytics. Misconfigured automation would affect response actions, not technique tagging. Automation rules are correct when you need to assign owners or close incidents automatically.

  • ✗

    The data connector for the source service is not ingesting the required fields.

    Why it's wrong here

    Missing connector fields would prevent an incident from being generated at all, or leave entities empty, rather than mis-tag a technique on an existing incident. Connector troubleshooting is correct when logs stop arriving or expected entities are absent from incidents.

  • ✓

    The analytics rule that generated the incident has the correct MITRE ATT&CK technique selected.

    Why this is correct

    MITRE ATT&CK technique tagging is defined on the analytics rule itself; if the rule lacks the correct technique mapping, generated incidents inherit nothing. Checking the rule's technique selection addresses the root cause of missing tags.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.