Courseiva

SC-200 Manage a security operations environment Practice Question

Your team uses Microsoft Defender XDR to manage incidents. You need to ensure that all incidents with a severity of 'High' are automatically assigned to a specific SOC analyst group. What should you configure?

⚠ Common exam trap

Test-takers frequently confuse Microsoft Sentinel playbooks with Defender XDR automation rules, assuming Sentinel's incident orchestration can be applied to Defender XDR incidents, but they are separate platforms with distinct automation mechanisms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule in Microsoft Defender XDR to automatically assign incidents.

Microsoft Defender XDR's automation rules allow you to define conditions (e.g., severity equals 'High') and actions (e.g., assign to a specific SOC analyst group) that are executed automatically when incidents are created or updated. This is the native, built-in mechanism for incident assignment without requiring external scripts, playbooks, or email-based workflows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set up an advanced hunting query to detect high severity incidents and send email.

    Why it's wrong here

    Advanced hunting queries are KQL-based searches for threat hunting across raw data; they can surface patterns but cannot natively trigger incident assignment. Sending an email from such a query would require external logic like a custom connector or Logic App, and it still would not update the incident owner. The native mechanism for automatic assignment is an automation rule, not an email notification.

  • ✓

    Create an automation rule in Microsoft Defender XDR to automatically assign incidents.

    Why this is correct

    Automation rules in Microsoft Defender XDR are the built-in mechanism for automatically applying actions—including assigning incidents to a specific owner or team—based on conditions like severity, detection source, or category. When an incident is created or updated, the rule evaluates it in real time and executes the assigned action, eliminating manual triage. This is the correct, supported way to enforce ownership policies centrally.

  • ✗

    Configure a playbook in Microsoft Sentinel triggered by incidents.

    Why it's wrong here

    Microsoft Sentinel playbooks are Azure Logic Apps that perform response actions (e.g., investigation steps, remediation) within Sentinel, not assignment of Defender XDR incidents. Defender XDR has its own incident-context automation rules; a Sentinel playbook would require cross-portal orchestration and does not natively handle Defender XDR assignments. Playbooks are also not designed to replace the focused, centralized assignment logic provided by automation rules.

  • ✗

    Use the 'New-MTPIncidentAssignment' cmdlet in a scheduled task.

    Why it's wrong here

    The cmdlet 'New-MTPIncidentAssignment' is not an official, supported PowerShell cmdlet in Microsoft Defender XDR; incident assignment is performed through the UI or the Microsoft Graph API. Scheduling a PowerShell job to run a made-up cmdlet would fail and, even if scripted via Graph, would not provide the event-driven, severity-based conditional logic that automation rules offer. Relying on a scheduled task also lacks auditability and real-time responsiveness.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.