Courseiva

SC-200 Manage a security operations environment Practice Question

You are configuring Microsoft Sentinel SOAR capabilities. You need to create an automated response that, when a critical incident is created, triggers a playbook that sends a message to a Teams channel. Which connector should you use in the playbook?

⚠ Common exam trap

It's easy for candidates to confuse the Microsoft Teams connector with the Microsoft Exchange connector, assuming both can send notifications, but Exchange is strictly for email, not Teams messaging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Teams connector

The Microsoft Teams connector is the correct choice because it enables the playbook to post messages directly to a Teams channel via an HTTP trigger and the Teams webhook action. This connector is specifically designed for sending notifications and messages to Teams, which aligns with the requirement to alert a channel when a critical incident is created.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Exchange connector

    Why it's wrong here

    The Microsoft Exchange connector in Microsoft Sentinel is for ingesting email messages, primarily for threat hunting and investigating phishing campaigns. It does not integrate with Microsoft Teams' messaging infrastructure, so it cannot perform SOAR actions like posting to a channel or sending adaptive cards. In the context of needing to notify a security team via Teams, the Exchange connector would require intermediate logic (e.g., a playbook that sends email to a Teams email address, which is not native) and is not the direct, supported action.

  • ✗

    Azure DevOps connector

    Why it's wrong here

    The Azure DevOps connector integrates with work items, such as bugs and tasks, enabling the creation of work items from incidents and linking them to development cycles. It does not provide a method to send real-time notifications or messages to a Teams channel, and its actions are scoped to project management workflows. While you could theoretically trigger a webhook, the connector itself does not have a 'send message' action, making it incorrect for this requirement.

  • ✓

    Microsoft Teams connector

    Why this is correct

    The Microsoft Teams connector in Sentinel automation rules can post messages to a Teams channel or send adaptive cards, which is the standard way to notify analysts of incidents. It supports actions such as 'Post message (V3)' that can include incident details, and it also allows for approval flows via Teams. This aligns with the requirement to configure SOAR capabilities for messaging a team.

  • ✗

    Microsoft Entra ID connector

    Why it's wrong here

    The Microsoft Entra ID (formerly Azure AD) connector provides identity-related actions like enabling or disabling a user account, resetting passwords, and retrieving group memberships. It has no built-in capability to send messages or channel notifications, so it is not applicable to a task requiring messaging in a team collaboration platform. While it could be used to query user information that might be included in a message, that would only be as part of a larger playbook that uses a different connector for the actual message.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.