mediumMultiple Choice
SC-100 Practice Question: A SOC team uses Microsoft Sentinel for incident…
A SOC team uses Microsoft Sentinel for incident management. They need to ensure that when a high-severity incident is created, a Teams message is sent to the security team and an email is sent to the IT manager. What is the most efficient way to achieve this?
⚠ Common exam trap
Candidates often confuse analytics rule configuration (which can only generate incidents or alerts) with automation rules (which handle post-creation actions like playbooks), leading them to incorrectly select Option A.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule in Sentinel that triggers a playbook to send the notifications.
Automation rules in Microsoft Sentinel can trigger a playbook (an Azure Logic Apps workflow) when an incident is created, allowing you to send a Teams message and an email simultaneously. This is the most efficient, automated approach without manual intervention or modifying the analytics rule itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the analytics rule to send notifications when an incident is created.
Why it's wrong here
Analytics rules are detection logic that generate alerts based on data queries; they do not have native actions to send emails or Teams messages. While you can attach automation rules to analytics rules, the analytics rule itself only defines conditions and severity, with notification delivery requiring a separate automation mechanism. Attempting to use an analytics rule directly for notifications misinterprets its role in the detection-to-response pipeline.
- ✓
Create an automation rule in Sentinel that triggers a playbook to send the notifications.
Why this is correct
Automation rules are the native orchestration layer in Microsoft Sentinel that run automatically when an incident is created or updated, and they can invoke a playbook as an action. A playbook, built on Azure Logic Apps, can send email, post to Teams, create a ticket, or call any API, making it the proper way to deliver notifications. This is the recommended pattern for automating incident response notifications without custom code.
- ✗
Use a workbook to display incidents and have a manual process to send notifications.
Why it's wrong here
Sentinel workbooks are interactive dashboards for visualizing and monitoring data; they do not execute background actions or trigger notifications on their own. Relying on a manual process to watch a workbook and then send notifications introduces latency and human error, defeating the purpose of automated SOC alerting. Automation rules and playbooks are the designed mechanisms for proactive, immediate notification delivery.
- ✗
Enable incident creation in the data connector settings.
Why it's wrong here
Data connectors are responsible only for ingesting logs and enabling data source integration, not for orchestrating incident responses or sending notifications. Some connectors include settings to generate alerts or incidents, but these are separate from notification actions and do not provide email/Teams delivery. Notification delivery must be handled by automation rules/playbooks, not by connector configuration.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.