Courseiva

SC-200 Respond to security incidents Practice Question

Your SOC uses Microsoft Sentinel. An analytics rule produces an incident, and your runbook requires that when a specific high-severity incident is created, a playbook must automatically post a summary to a Microsoft Teams channel and create a tracking task. You need the playbook to run without a human clicking anything. What should you configure?

⚠ Common exam trap

The trap here is assuming an analytics rule can call a playbook directly, when playbook execution is wired through automation rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An automation rule with the trigger When incident is created and an action that runs the playbook.

Automation rules are the Microsoft Sentinel component that watches for incident creation or update events and can launch playbooks automatically when conditions match. Pairing an incident-created trigger with a playbook action delivers the unattended Teams notification and task creation the runbook demands. Analytics rules, workbooks, and manual triggers either detect, display, or require human initiation, so none provides the event-driven response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A scheduled analytics rule that calls the playbook from within its query logic.

    Why it's wrong here

    Analytics rules detect and generate alerts and incidents; they do not contain a mechanism to invoke playbooks from inside query logic. Playbook invocation is handled by automation rules or by manual run from the incident. Expecting the query to call a playbook misunderstands where automation is wired, so the Teams summary and task would never be triggered by the rule itself.

  • ✓

    An automation rule with the trigger When incident is created and an action that runs the playbook.

    Why this is correct

    Automation rules in Microsoft Sentinel evaluate incident conditions and can invoke playbooks automatically when their trigger conditions match, such as on incident creation with a specific severity or title. This satisfies the runbook requirement that no analyst clicks anything. The playbook then performs the Teams posting and task creation through its connectors, so the response is fully automated and repeatable for every matching incident.

  • ✗

    A workbook that refreshes on a schedule and triggers the playbook through a data connector.

    Why it's wrong here

    Workbooks are visualization and reporting artifacts built on queries; they have no execution path that launches playbooks. A data connector ingests telemetry into the workspace and likewise cannot start a response workflow. This combination would display incident data but would not post to Teams or create the tracking task automatically, so the runbook requirement would go unmet.

  • ✗

    A playbook with an HTTP trigger that an analyst runs manually from the incident page.

    Why it's wrong here

    A playbook with a manual or HTTP trigger requires someone to start it, which directly contradicts the requirement that no human clicks anything. While HTTP-triggered playbooks are useful for external orchestration, they do not fire on incident creation by themselves. The scenario needs event-driven automation, so a manually started playbook leaves the Teams post and task creation dependent on analyst action.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.