Courseiva

SC-200 Manage a security operations environment Practice Question

You are a security operations analyst using Microsoft Sentinel. You need to configure a playbook that automatically posts a message to a Microsoft Teams channel when a high-severity incident is created. Which two actions must you perform? (Choose two.)

⚠ Common exam trap

Candidates often confuse the trigger condition (incident created vs. updated) or using the wrong connector (Outlook instead of Teams).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule that triggers when an incident is created and has a condition for severity equals High.

To automatically post a message to Microsoft Teams when a high-severity incident is created in Microsoft Sentinel, you need an automation rule that triggers on incident creation, checks the severity, and runs a playbook. The playbook must use the Microsoft Teams connector to post the message to the desired channel. The automation rule provides the trigger and condition, while the playbook performs the action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a playbook that uses the Office 365 Outlook connector and sends an email to the SOC team.

    Why it's wrong here

    The requirement is to post a message to a Microsoft Teams channel, not to send an email. Using the Office 365 Outlook connector would send an email, which does not meet the requirement. The correct connector is Microsoft Teams.

  • ✗

    Create a playbook that uses the Microsoft Sentinel connector and retrieves incident details.

    Why it's wrong here

    While retrieving incident details might be useful for the message content, it is not a required action to post a message to Teams. The essential components are the automation rule to trigger the playbook and the Teams connector to post the message. The Sentinel connector alone does not post to Teams.

  • ✓

    Create an automation rule that triggers when an incident is created and has a condition for severity equals High.

    Why this is correct

    This is correct because to automatically run a playbook based on incident creation and severity, you need an automation rule. The automation rule can have a condition to check the severity and then an action to run the playbook. This ensures the playbook only runs for high-severity incidents.

  • ✓

    Create a playbook that uses the Microsoft Teams connector and posts a message to the desired channel.

    Why this is correct

    This is correct because the playbook contains the actual logic to post to Teams. You need to use the Microsoft Teams connector and configure the action to post a message to the specified channel. The playbook will be triggered by the automation rule.

  • ✗

    Create an automation rule that triggers when an incident is updated and has a condition for severity equals High.

    Why it's wrong here

    The requirement is to post a message when a high-severity incident is created, not updated. Using the 'incident updated' trigger would cause the playbook to run on updates, potentially leading to multiple messages. The correct trigger is 'incident created'.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.