SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit.
```json
{
"id": "playbook-logic-app",
"triggers": {
"When_a_response_to_a_Microsoft_Sentinel_alert_is_triggered": {
"kind": "Microsoft.EventGrid",
"inputs": {
"body": {
"alert": {
"properties": {
"providerAlertId": "@triggerBody()?['data']?['essentials']?['alertId']",
"correlationKey": "@triggerBody()?['data']?['essentials']?['correlationKey']"
}
}
}
}
}
},
"actions": {
"Compose_Teams_message": {
"kind": "Microsoft.Teams.PostMessage",
"inputs": {
"message": "Alert ID: @{triggerBody()?['data']?['essentials']?['alertId']}",
"recipient": "security-team-channel"
}
}
}
}
```Refer to the exhibit. You have a Logic Apps playbook that triggers on Microsoft Sentinel alerts. The playbook is not posting messages to Teams. What is the most likely cause?
⚠ Common exam trap
It's easy for candidates to assume authentication issues (Option B) are the default cause for Teams failures, but the question's context of 'not posting messages' without errors points to a trigger mismatch rather than a connectivity problem.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The playbook is using the wrong trigger type.
The playbook is triggered on Microsoft Sentinel alerts, but Logic Apps requires a specific trigger type to process these alerts correctly. The most likely cause is that the playbook uses a generic HTTP trigger instead of the 'Microsoft Sentinel Incident' or 'Microsoft Sentinel Alert' trigger, which is designed to parse the alert payload and provide the necessary context for downstream actions like posting to Teams. Without the correct trigger, the playbook may not receive the alert data or may fail to execute the Teams connector properly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The playbook is using the wrong trigger type.
Why this is correct
The playbook is using the wrong trigger type. A Logic Apps playbook designed for Microsoft Sentinel automation must use the 'When a Microsoft Sentinel alert is created' trigger (or the incident trigger in newer implementations), not a generic HTTP, schedule, or manual trigger. With the wrong trigger, the runtime does not supply the Sentinel alert schema, so all subsequent references to alert properties—such as the alert ID or title—resolve to empty values and the playbook fails before any Teams action executes. The fix is to replace the trigger with the Sentinel-specific trigger so the correct alert payload is bound to the workflow.
- ✗
The Teams connector is not authenticated.
Why it's wrong here
The Teams connector is not authenticated. Authentication failures from the Teams connector would produce a distinct HTTP 401 or 403 status in the run history, along with a Teams-specific error message indicating missing or expired credentials. The exhibit shows no such credential error; instead, the failure is at an earlier stage where the trigger has not delivered the alert payload to the playbook. Even if the Teams connection were fully authenticated, the playbook would still fail because the trigger type is incompatible with Sentinel's invocation, so authentication is not the root cause.
- ✗
The trigger body is not referencing the correct alert ID.
Why it's wrong here
The trigger body is not referencing the correct alert ID. The expression used in the playbook—such as `triggerBody()?['properties']?['alert']?['alertId']`—matches the schema of the Sentinel alert trigger, so the reference itself is syntactically and structurally correct. If the alert ID were misreferenced, the playbook would run but simply use an empty or undefined value for that property, rather than failing at the trigger binding step. The reported error indicates no alert payload was received at all, which points to the trigger type being wrong, not to an incorrect property path.
- ✗
The JSON syntax is invalid.
Why it's wrong here
The JSON syntax is invalid. The playbook definition in the exhibit uses proper JSON formatting with correct braces, commas, quotes, and key-value pairs, and if it contained invalid JSON, Logic Apps would reject the definition during save or submit rather than allowing the playbook to run and then fail. A runtime error about an empty trigger body is not a JSON parse error—it is a data-binding error caused by the trigger not supplying the expected Sentinel alert schema. Therefore, invalid JSON can be ruled out definitively as the cause.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.