PL-900 Practice Question: Demonstrate the capabilities of Power Automate
Your organization uses Power Automate to automate the creation of support tickets in ServiceNow when a critical alert is triggered in Microsoft Sentinel. The flow uses the 'When a new alert is created' trigger from Sentinel. The flow runs but no tickets are created. You check the Sentinel log and see that alerts are being generated. What should you investigate first?
⚠ Common exam trap
PL-900 often tests the distinction between 'the flow runs but nothing happens' (trigger condition/filter problem) versus 'the flow fails' (connector or action problem) — candidates incorrectly jump to connector configuration when the flow is actually running.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the trigger condition or filter query.
The flow runs successfully but produces no tickets, which means the trigger is firing but the condition inside the flow is filtering out the alerts. Since Sentinel confirms alerts are being generated, the most likely cause is that the trigger's condition or filter query (e.g., severity = High, or a specific analytics rule name) does not match the alerts being produced. Reviewing the trigger condition is the correct first step because it isolates whether the flow logic is excluding the alerts before the ServiceNow action ever executes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify that the flow is enabled.
Why it's wrong here
A disabled flow would produce no run history at all, yet the stem states the flow runs, so enablement is already satisfied. It tempts because a switched-off flow is a common cause of silent non-execution, and checking status is a quick first step in ordinary troubleshooting.
- ✗
Ensure that the Sentinel data connector is properly installed.
Why it's wrong here
Alerts already appear in the Sentinel log, proving ingestion works, so the connector is not the fault. It tempts because a missing or misconfigured data connector is a frequent reason Sentinel shows nothing, but here the trigger fires and the failure lies downstream.
- ✓
Review the trigger condition or filter query.
Why this is correct
The Sentinel trigger fires only when an alert matches its configured conditions. If a filter query or trigger condition excludes the generated alerts, the flow never starts, so no ServiceNow tickets appear despite alerts existing. Reviewing these settings first confirms whether the trigger is actually firing.
- ✗
Check if the ServiceNow connector is configured with the correct instance.
Why it's wrong here
The stem says the flow runs, so the trigger fires; a wrong ServiceNow instance would surface as an action failure in run history, not as no tickets. It tempts because connector misconfiguration is a common cause of failed ticket creation, but the question asks what to investigate first.
Go deeper
Related to this question
About these practice questions
One of 701 original PL-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.