Courseiva

SC-200 Manage a security operations environment Practice Question

You are a security administrator for a multinational company using Microsoft Sentinel. You need to ensure that critical incidents are automatically escalated to the on-call team via email and SMS. The on-call schedule uses Microsoft Teams channel. What is the most efficient way to achieve this?

⚠ Common exam trap

Test-takers frequently assume automation rules can natively send emails or SMS, but they can only trigger playbooks or modify incident properties, requiring a Logic App for actual notification delivery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Build a playbook using Microsoft Teams connector to post a message in the on-call channel with an adaptive card that allows acknowledge and escalate.

It uses a Microsoft Teams connector playbook triggered by an automation rule to post an adaptive card in the on-call channel. This allows the on-call team to acknowledge or escalate the incident directly from Teams, fulfilling the requirement for email and SMS escalation through the Teams channel schedule. Automation rules in Sentinel can trigger playbooks based on incident creation or update, making this the most efficient integrated approach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an automation rule that sends email directly to the on-call team.

    Why it's wrong here

    Automation rules in Microsoft Sentinel are designed to manage incident triage—such as assigning, tagging, or changing severity—and to trigger playbooks. They do not have a native action to send an email directly; email can only be delivered as part of a playbook that uses a connector like Office 365 Outlook. Without a playbook to host the email-sending step, this option is incomplete and therefore incorrect.

  • ✓

    Build a playbook using Microsoft Teams connector to post a message in the on-call channel with an adaptive card that allows acknowledge and escalate.

    Why this is correct

    This is the correct approach because a playbook—built on Azure Logic Apps—can be triggered by an automation rule when an incident is created. The playbook uses the Microsoft Teams connector to post an adaptive card to the on-call channel, and the card's buttons (Acknowledge/Escalate) invoke further logic, such as updating the incident status or notifying a second-tier team. This provides a closed-loop, interactive notification workflow rather than a one-way message.

  • ✗

    Configure the analytics rule to send an email when the incident is created.

    Why it's wrong here

    Analytics rules in Microsoft Sentinel are responsible for querying data and generating alerts/incidents; they do not have a configuration option to send emails upon incident creation. Incident creation is the end of an analytics rule's core job, and any email delivery must be handled downstream by a playbook triggered via an automation rule. Therefore, this option conflates detection logic with notification logic and is incorrect.

  • ✗

    Use a workbook to display critical incidents and expect the team to monitor it.

    Why it's wrong here

    Workbooks are interactive dashboards used for visualizing Sentinel data and trends, but they are passive and require a user to open and monitor them. They cannot actively send notifications or ensure that on-call staff are alerted in real time. Relying on a workbook for critical incident notification introduces unacceptable delay and depends on constant human attention, making it an incorrect solution for immediate response.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.