SC-200 Manage a security operations environment Practice Question
Exhibit
{
"properties": {
"displayName": "Incident Response Playbook",
"trigger": {
"type": "HttpTrigger",
"kind": "Default"
},
"definitions": {
"$schema": "https://schema.management.azure.com/providers/Microsoft.Logic/workflows/definitions/2019-01-01-preview/schema.json",
"actions": {
"Send_email": {
"type": "ApiConnection",
"inputs": {
"host": {
"connectionName": "office365"
},
"method": "post",
"path": "/v2/Mail"
}
}
}
}
}
}Refer to the exhibit. You have a Microsoft Sentinel playbook created as shown. When you test the playbook manually, it sends an email successfully. However, when an incident triggers the playbook via an automation rule, the email is not sent. What is the most likely cause?
⚠ Common exam trap
A common mix-up: candidates assume any playbook can be triggered by an automation rule, overlooking that the playbook must use the dedicated Microsoft Sentinel trigger connector, not a generic HTTP trigger.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The playbook uses an HTTP trigger instead of a Microsoft Sentinel trigger.
The exhibit shows a playbook that begins with an HTTP trigger, not a Microsoft Sentinel trigger. When an incident triggers the playbook via an automation rule, Sentinel expects the playbook to start with a Microsoft Sentinel trigger (e.g., 'When a response to a Microsoft Sentinel incident is triggered'). An HTTP trigger requires an external HTTP request to start the playbook, which the automation rule does not provide, so the playbook never executes the email action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The playbook does not have permission to read incidents.
Why it's wrong here
Manual testing of a playbook executes the logic app directly from its HTTP trigger endpoint and does not require the playbook to read an incident, so the absence of incident-read permissions would not prevent the test from completing. In an automation-rule run, Sentinel would supply the incident payload, and lack of permissions could cause failure later—but this does not explain why the playbook cannot be added to the automation rule. The root issue is trigger compatibility, not permissions.
- ✓
The playbook uses an HTTP trigger instead of a Microsoft Sentinel trigger.
Why this is correct
Microsoft Sentinel automation rules can only invoke Logic Apps that start with a Microsoft Sentinel trigger—either the 'Microsoft Sentinel Incident' trigger or the 'Microsoft Sentinel Alert' trigger—because those triggers receive the incident/alert payload and register the playbook as a Sentinel playbook. The exhibit shows an HTTP trigger ('When a HTTP request is received'), which is a generic Logic Apps trigger; although it can be tested manually by sending an HTTP POST to the endpoint, it is not registered with Microsoft Sentinel as a playbook and therefore is not available for selection in an automation rule. Replacing the HTTP trigger with a Microsoft Sentinel Incident trigger would make the playbook eligible for automation-rule use.
- ✗
The email action is not configured correctly.
Why it's wrong here
Manual test success proves the email action is functioning correctly: the run completed and sent the email using the configured Office 365 Outlook connection and parameters. If the email action had an invalid recipient, malformed body, or broken connection reference, the playbook would fail at that step during the manual test. Therefore, an incorrectly configured email action cannot explain why the playbook is unavailable in Sentinel automation rules.
- ✗
The Office 365 connection is not authorized.
Why it's wrong here
The Office 365 connection was successfully used during the manual test, which means the connection is authorized and has valid credentials; an unauthorized connection would generate an authentication error before or during the email step. Azure Logic Apps stores the connection with a consent/authorization token, and the manual run validates that token is still valid for the Office 365 Outlook API. Since authorization is not in question, this cannot be the cause of the playbook not appearing in the automation rule.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.