SC-200 Manage a security operations environment Practice Question
You are configuring Microsoft Sentinel SOAR capabilities. You need to create an automated response that, when a critical incident is created, triggers a playbook that sends a message to a Teams channel. Which connector should you use in the playbook?
⚠ Common exam trap
It's easy for candidates to confuse the Microsoft Teams connector with the Microsoft Exchange connector, assuming both can send notifications, but Exchange is strictly for email, not Teams messaging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Teams connector
The Microsoft Teams connector is the correct choice because it enables the playbook to post messages directly to a Teams channel via an HTTP trigger and the Teams webhook action. This connector is specifically designed for sending notifications and messages to Teams, which aligns with the requirement to alert a channel when a critical incident is created.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Exchange connector
Why it's wrong here
The Microsoft Exchange connector in Microsoft Sentinel is for ingesting email messages, primarily for threat hunting and investigating phishing campaigns. It does not integrate with Microsoft Teams' messaging infrastructure, so it cannot perform SOAR actions like posting to a channel or sending adaptive cards. In the context of needing to notify a security team via Teams, the Exchange connector would require intermediate logic (e.g., a playbook that sends email to a Teams email address, which is not native) and is not the direct, supported action.
- ✗
Azure DevOps connector
Why it's wrong here
The Azure DevOps connector integrates with work items, such as bugs and tasks, enabling the creation of work items from incidents and linking them to development cycles. It does not provide a method to send real-time notifications or messages to a Teams channel, and its actions are scoped to project management workflows. While you could theoretically trigger a webhook, the connector itself does not have a 'send message' action, making it incorrect for this requirement.
- ✓
Microsoft Teams connector
Why this is correct
The Microsoft Teams connector in Sentinel automation rules can post messages to a Teams channel or send adaptive cards, which is the standard way to notify analysts of incidents. It supports actions such as 'Post message (V3)' that can include incident details, and it also allows for approval flows via Teams. This aligns with the requirement to configure SOAR capabilities for messaging a team.
- ✗
Microsoft Entra ID connector
Why it's wrong here
The Microsoft Entra ID (formerly Azure AD) connector provides identity-related actions like enabling or disabling a user account, resetting passwords, and retrieving group memberships. It has no built-in capability to send messages or channel notifications, so it is not applicable to a task requiring messaging in a team collaboration platform. While it could be used to query user information that might be included in a message, that would only be as part of a larger playbook that uses a different connector for the actual message.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.