Courseiva

SC-200 Manage a security operations environment Practice Question

You are a security operations analyst at a company that uses Microsoft Sentinel. You need to ensure that when a specific analytics rule generates an incident, a playbook is automatically triggered to post a message in a Microsoft Teams channel. What should you configure?

⚠ Common exam trap

The trap here is thinking that an analytics rule can directly trigger a playbook or that a Teams workflow can monitor Sentinel incidents, bypassing the need for an automation rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An automation rule that triggers the playbook when the incident is created.

To automatically trigger a playbook when a specific analytics rule creates an incident, you need an automation rule. Automation rules in Microsoft Sentinel respond to incident creation and can invoke playbooks. The playbook can then use the Microsoft Teams connector to post a message. This is the standard and supported method for this automation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A workflow in Microsoft Teams that monitors the Sentinel incident queue.

    Why it's wrong here

    Microsoft Teams workflows do not natively monitor Microsoft Sentinel incidents. While you can create a Teams workflow that uses a webhook, it would require manual setup and is not the standard method. The proper approach is to use an automation rule that triggers a playbook, which then posts to Teams via the Teams connector.

  • ✗

    A playbook that is triggered by the analytics rule directly.

    Why it's wrong here

    Analytics rules do not directly trigger playbooks; they generate incidents. Playbooks are triggered by automation rules or by incident creation triggers in Azure Logic Apps. Configuring the analytics rule alone cannot invoke a playbook; an automation rule is required to bridge the incident to the playbook.

  • ✓

    An automation rule that triggers the playbook when the incident is created.

    Why this is correct

    Automation rules in Microsoft Sentinel can trigger playbooks based on incident creation. By creating an automation rule that runs when the specific analytics rule generates an incident, you can automatically invoke the playbook that posts to Microsoft Teams. This is the correct method to achieve the required automation.

  • ✗

    A scheduled query rule in Azure Monitor that detects the incident and calls the playbook.

    Why it's wrong here

    Scheduled query rules in Azure Monitor are used for creating alerts based on log queries, not for triggering playbooks based on Sentinel incidents. They operate at the Log Analytics level and do not have direct integration with Sentinel incidents. Using this would add unnecessary complexity and not meet the requirement.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.