Courseiva
mediumMultiple Choice

SC-200 Practice Question: A security analyst wants to configure a playbook…

A security analyst wants to configure a playbook in Microsoft Sentinel that runs automatically when a specific alert is generated. Which trigger concept is used to invoke the playbook?

⚠ Common exam trap

Many exam-takers confuse the automation rule (which invokes the playbook) with the actual trigger mechanism, leading them to choose 'Automation rule trigger' instead of recognizing that the playbook itself is triggered by an Azure Logic Apps trigger.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Logic Apps trigger

In Microsoft Sentinel, playbooks are built on Azure Logic Apps, and the correct trigger to invoke a playbook automatically when an alert is generated is the Azure Logic Apps trigger. This trigger listens for the Sentinel alert creation event and initiates the playbook workflow. The other options are not valid trigger concepts within Sentinel's architecture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Logic Apps trigger

    Why this is correct

    This is the correct answer because Microsoft Sentinel playbooks are built on Azure Logic Apps, and the playbook workflow itself begins with a built-in Logic Apps trigger—specifically the 'When a response to a Microsoft Sentinel alert is triggered' trigger. This trigger receives the alert payload via the Sentinel connector and initiates the Logic App. The term 'Azure Logic Apps trigger' accurately reflects the underlying technology and distinguishes it from other trigger types in Sentinel.

  • ✗

    Sentinel trigger

    Why it's wrong here

    Although 'Sentinel trigger' sounds plausible, it is not an actual trigger type in Azure Logic Apps. Microsoft Sentinel playbooks are implemented as Logic Apps workflows, and the underlying trigger is a Logic Apps connector trigger specifically named 'When a response to a Microsoft Sentinel alert is triggered' or similar. There is no distinct 'Sentinel trigger' separate from Logic Apps; the term incorrectly implies a dedicated trigger that does not exist in the Azure platform.

  • ✗

    Alert trigger

    Why it's wrong here

    'Alert trigger' is an overly generic and misleading term because Logic Apps and Sentinel both use many different alert-related triggers across various services. In the context of a Microsoft Sentinel playbook, the precise trigger is the Logic Apps 'Microsoft Sentinel alert' trigger, which is part of the Sentinel data connector, not a standalone 'Alert trigger'. The generic name fails to capture the correct trigger category and is therefore inaccurate.

  • ✗

    Automation rule trigger

    Why it's wrong here

    Automation rules are a Microsoft Sentinel feature that define conditions and actions, including the ability to run a playbook in response to an alert or incident. However, the automation rule does not serve as the playbook's trigger; it merely invokes the playbook by causing its Logic Apps trigger to fire. The playbook's first step is still a Logic Apps trigger, not an 'Automation rule trigger'. Therefore, referring to an 'Automation rule trigger' confuses the external automation mechanism with the actual workflow trigger inside the playbook.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.