Courseiva

SC-200 Manage a security operations environment Practice Question

A SOC manager wants to implement a new workflow where high-severity Microsoft Defender for Cloud Apps alerts are automatically sent to a Teams channel for immediate action. The solution must not require custom code. What should the manager configure?

⚠ Common exam trap

Watch out — candidates often confuse Microsoft Defender XDR's email notification rules with the ability to send Teams messages, or assume Power Automate is the correct low-code solution, but the question's requirement for no custom code and direct integration with Microsoft Defender for Cloud Apps alerts points specifically to Sentinel's automation rules with playbooks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule in Microsoft Sentinel with a playbook that posts to Teams

Microsoft Sentinel's automation rules can trigger a playbook (built on Azure Logic Apps) when a high-severity alert is generated, and the playbook can post a message to a Teams channel without requiring custom code. This directly meets the requirement of automatically sending high-severity Microsoft Defender for Cloud Apps alerts to Teams for immediate action, leveraging built-in connectors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Microsoft Power Automate to monitor the alerts and send a Teams message

    Why it's wrong here

    Microsoft Power Automate can create cloud flows to monitor alert sources, but doing so for Defender for Cloud Apps requires a premium connector and often incurs additional licensing costs. Furthermore, a stand-alone Power Automate flow lacks direct integration with Microsoft Sentinel's incident lifecycle, so it cannot leverage automation rules, custom entity extraction, or built-in alert correlation. The workflow would also need a separate polling mechanism, making it less reliable and more complex than using Sentinel's native automation rules with a playbook.

  • ✗

    Configure a rule in Microsoft Defender XDR to send email notifications

    Why it's wrong here

    Microsoft Defender XDR supports email notification rules for alerts generated by its own security products, such as Defender for Endpoint or Defender for Office 365, but these rules are not designed for Defender for Cloud Apps alerts. Even if a rule could be configured to send an email, the requirement explicitly asks for a Teams message, which Defender XDR's alert notification settings do not provide. Since the workflow must post to Teams, relying on an email-based rule would fail the stated business requirement.

  • ✓

    Create an automation rule in Microsoft Sentinel with a playbook that posts to Teams

    Why this is correct

    The recommended approach is to ingest Defender for Cloud Apps alerts into Microsoft Sentinel using the Defender for Cloud Apps data connector, which normalizes the alerts as Sentinel incidents. Once ingested, a Sentinel automation rule can be created to run when an incident is generated, triggering an Azure Logic Apps-based playbook that posts a formatted message to a Microsoft Teams channel. This pipeline is fully integrated, leverages Sentinel's native threat intelligence and incident management, and can include enrichment steps before the Teams notification is sent.

  • ✗

    Configure Microsoft Entra ID to send the alerts to Teams

    Why it's wrong here

    Microsoft Entra ID (formerly Azure AD) primarily publishes identity-related security alerts, such as risky sign-in and risky user detections, and it does not ingest or manage Defender for Cloud Apps alerts. Its alert notifications are delivered through the Microsoft Entra ID portal or via Microsoft Graph, and they do not include native integration to send messages directly to a Teams channel. Entra ID also lacks the automation and playbook capabilities needed to satisfy this workflow, making it an unsuitable destination for this integration.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Sentinel and you have a playbook that sends an email notification when a high-severity incident is created. You want to ensure that the playbook only runs for incidents that are not already assigned to a user. What should you configure?

easy
  • A.Set the playbook trigger to 'When an incident is created' and add a condition inside
  • B.Add a condition in the playbook to check if the incident is assigned
  • ✓ C.Configure the automation rule trigger to include a condition for 'Incident owner equals null'
  • D.Modify the analytics rule to only generate unassigned incidents

Why C: Automation rules in Microsoft Sentinel can include conditions that filter which incidents trigger a playbook. By configuring the automation rule with a condition for 'Incident owner equals null', the playbook will only run for incidents that are unassigned, ensuring that already assigned incidents are not processed. This approach is efficient and avoids unnecessary execution of the playbook.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.