Courseiva

SC-200 Respond to security incidents Practice Question

Your team uses Microsoft Sentinel to manage incidents. You want to automatically assign incidents with a severity of 'High' to the Tier 2 security team. Which feature should you configure?

⚠ Common exam trap

SC-200 often tests the confusion between automation rules (incident orchestration: assign, tag, close) and playbooks (multi-step remediation workflows), so candidates pick Playbook when the task is simple incident assignment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automation rule

Automation rules in Microsoft Sentinel are designed to perform lightweight incident-level orchestration such as assigning owners, changing severity, adding tags, or closing incidents based on conditions. To auto-assign High-severity incidents to Tier 2, you create an automation rule with a condition on severity and an action to assign the owner. This is exactly the native, no-code mechanism for incident triage routing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Playbook

    Why it's wrong here

    Playbooks run automated response actions after an incident is created, so they cannot set the owner during creation. They are tempting because they orchestrate remediation and enrichment, and would be correct for triggering notifications or containment steps once a High incident already exists.

  • ✗

    Analytics rule

    Why it's wrong here

    Analytics rules generate alerts and incidents from queries, but their entity mapping and automation settings do not assign an owner to the resulting incident. They are tempting because they define incident creation, and would be correct for detecting the activity that produces High-severity incidents in the first place.

  • ✓

    Automation rule

    Why this is correct

    Automation rules in Microsoft Sentinel trigger on incident creation and can set owner, status and severity automatically. Configuring a rule that matches severity equals High and assigns the Tier 2 team satisfies the automatic assignment requirement without manual triage.

  • ✗

    Workbook

    Why it's wrong here

    Workbooks render visual dashboards and reports over Log Analytics data; they hold no incident-mutation logic and cannot assign owners. They are tempting because they display incident metrics, and would be correct for building a security posture overview rather than automating triage routing.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.