Drag or tap steps into the slots.
SC-200 Practice Question: Arrange the steps to configure a Microsoft…
Arrange the steps to configure a Microsoft Sentinel playbook (automation) using Azure Logic Apps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Step 1: Create a Logic App in Azure. Step 2: Configure the Sentinel trigger (e.g., "When a response to an Azure Sentinel incident is triggered"). Step 3: Add actions (e.g., send email, create ticket). Step 4: Save the playbook and link it to a Microsoft Sentinel automation rule.
Playbooks are Logic Apps that automate responses; they must be created and then linked to Sentinel automation rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Step 1: Create a Logic App in Azure. Step 2: Configure the Sentinel trigger (e.g., "When a response to an Azure Sentinel incident is triggered"). Step 3: Add actions (e.g., send email, create ticket). Step 4: Save the playbook and link it to a Microsoft Sentinel automation rule.
Why this is correct
This is the correct order because you must first create the Logic App, then define the trigger that connects it to Sentinel incidents, then add the desired actions, and finally associate the playbook with an automation rule to activate it.
- ✗
Step 1: Create a Microsoft Sentinel automation rule. Step 2: Create a Logic App. Step 3: Add actions. Step 4: Save and test.
Why it's wrong here
This order is invalid because the Microsoft Sentinel automation rule's 'Run playbook' action requires you to select an already deployed Logic App playbook from a dropdown; if the Logic App has not yet been created, the rule cannot be saved with a playbook reference. Furthermore, the automation rule's configuration includes permissions for the playbook's managed identity, which are assigned when the playbook is created, not before. The rule is the runtime invocation layer, not the definition layer, so it must come last after the Logic App and its trigger are fully configured and saved.
- ✗
Step 1: Create a Logic App. Step 2: Add actions. Step 3: Configure the Sentinel trigger. Step 4: Link to automation rule.
Why it's wrong here
Configuring the Sentinel trigger is a prerequisite for adding actions because the Logic Apps designer uses the trigger's output schema to expose dynamic content such as the incident ID, severity, owner, and title. If you add actions first, they have no data source to draw from, and the workflow will fail validation because the trigger must be the first step of any Logic App. Additionally, the trigger's connection details and polling or webhook behavior determine how the playbook is initiated, so actions cannot be sensibly authored before that context exists.
- ✗
Step 1: Configure Sentinel trigger. Step 2: Create a Logic App. Step 3: Add actions. Step 4: Link to automation rule.
Why it's wrong here
You cannot configure a Sentinel trigger in isolation because the trigger is a property of a Logic App resource—the Logic App must be provisioned in Azure before you can open its workflow designer and define the trigger. Attempting to create a trigger first would require a resource to contain it; there is no standalone Sentinel trigger service. Even if you think of the connector as a trigger type, it only exists inside a Logic App's workflow, so Step 1 must be the resource creation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.