SC-200 Manage a security operations environment Practice Question
You are a security operations analyst at a company that uses Microsoft Sentinel. You need to ensure that when a specific analytics rule generates an incident, a playbook is automatically triggered to post a message in a Microsoft Teams channel. What should you configure?
⚠ Common exam trap
The trap here is thinking that an analytics rule can directly trigger a playbook or that a Teams workflow can monitor Sentinel incidents, bypassing the need for an automation rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An automation rule that triggers the playbook when the incident is created.
To automatically trigger a playbook when a specific analytics rule creates an incident, you need an automation rule. Automation rules in Microsoft Sentinel respond to incident creation and can invoke playbooks. The playbook can then use the Microsoft Teams connector to post a message. This is the standard and supported method for this automation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A workflow in Microsoft Teams that monitors the Sentinel incident queue.
Why it's wrong here
Microsoft Teams workflows do not natively monitor Microsoft Sentinel incidents. While you can create a Teams workflow that uses a webhook, it would require manual setup and is not the standard method. The proper approach is to use an automation rule that triggers a playbook, which then posts to Teams via the Teams connector.
- ✗
A playbook that is triggered by the analytics rule directly.
Why it's wrong here
Analytics rules do not directly trigger playbooks; they generate incidents. Playbooks are triggered by automation rules or by incident creation triggers in Azure Logic Apps. Configuring the analytics rule alone cannot invoke a playbook; an automation rule is required to bridge the incident to the playbook.
- ✓
An automation rule that triggers the playbook when the incident is created.
Why this is correct
Automation rules in Microsoft Sentinel can trigger playbooks based on incident creation. By creating an automation rule that runs when the specific analytics rule generates an incident, you can automatically invoke the playbook that posts to Microsoft Teams. This is the correct method to achieve the required automation.
- ✗
A scheduled query rule in Azure Monitor that detects the incident and calls the playbook.
Why it's wrong here
Scheduled query rules in Azure Monitor are used for creating alerts based on log queries, not for triggering playbooks based on Sentinel incidents. They operate at the Log Analytics level and do not have direct integration with Sentinel incidents. Using this would add unnecessary complexity and not meet the requirement.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.