SC-200 Respond to security incidents Practice Question
Your team uses Microsoft Sentinel to manage incidents. You want to automatically assign incidents with a severity of 'High' to the Tier 2 security team. Which feature should you configure?
⚠ Common exam trap
SC-200 often tests the confusion between automation rules (incident orchestration: assign, tag, close) and playbooks (multi-step remediation workflows), so candidates pick Playbook when the task is simple incident assignment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automation rule
Automation rules in Microsoft Sentinel are designed to perform lightweight incident-level orchestration such as assigning owners, changing severity, adding tags, or closing incidents based on conditions. To auto-assign High-severity incidents to Tier 2, you create an automation rule with a condition on severity and an action to assign the owner. This is exactly the native, no-code mechanism for incident triage routing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Playbook
Why it's wrong here
Playbooks run automated response actions after an incident is created, so they cannot set the owner during creation. They are tempting because they orchestrate remediation and enrichment, and would be correct for triggering notifications or containment steps once a High incident already exists.
- ✗
Analytics rule
Why it's wrong here
Analytics rules generate alerts and incidents from queries, but their entity mapping and automation settings do not assign an owner to the resulting incident. They are tempting because they define incident creation, and would be correct for detecting the activity that produces High-severity incidents in the first place.
- ✓
Automation rule
Why this is correct
Automation rules in Microsoft Sentinel trigger on incident creation and can set owner, status and severity automatically. Configuring a rule that matches severity equals High and assigns the Tier 2 team satisfies the automatic assignment requirement without manual triage.
- ✗
Workbook
Why it's wrong here
Workbooks render visual dashboards and reports over Log Analytics data; they hold no incident-mutation logic and cannot assign owners. They are tempting because they display incident metrics, and would be correct for building a security posture overview rather than automating triage routing.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.