SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit.
```json
{
"properties": {
"displayName": "DailyReport",
"description": "Sends daily security report",
"triggers": [
{
"type": "Recurrence",
"recurrence": {
"frequency": "Day",
"interval": 1,
"schedule": {
"hours": [8],
"minutes": [0]
}
}
}
],
"actions": [
{
"type": "SendEmail",
"inputs": {
"host": {
"connectionName": "office365",
"operationId": "SendEmailV2"
},
"parameters": {
"to": "security@contoso.com",
"subject": "Daily Security Report",
"body": "Report generated."
}
}
}
]
}
}
```You have a Microsoft Sentinel automation rule that triggers a playbook. The playbook definition is shown in the exhibit. The playbook runs but no email is sent. What is the most likely cause?
⚠ Common exam trap
Watch out — candidates often assume any playbook that runs will work with an automation rule, but the trigger type must match the automation rule's invocation method; a recurrence trigger runs independently and does not receive the incident context, causing the email to fail silently.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The playbook uses a recurrence trigger instead of a Microsoft Sentinel trigger.
The playbook uses a recurrence trigger, which means it runs on a schedule (e.g., every hour) rather than being invoked by a Microsoft Sentinel incident or alert. A Microsoft Sentinel automation rule can only trigger a playbook that has a Microsoft Sentinel trigger (e.g., 'When a response to a Microsoft Sentinel incident is triggered'). Without the correct trigger, the playbook will execute on its schedule but will not receive the incident context or be invoked by the automation rule, so no email is sent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The JSON syntax is invalid.
Why it's wrong here
The JSON syntax is valid in this scenario. A malformed JSON payload would prevent the automation rule from being created or saved in Microsoft Sentinel, but the rule is already active and firing. Since the rule exists and triggers normally, the JSON structure cannot be the cause of the playbook not executing with incident context.
- ✗
The email operation 'SendEmailV2' is deprecated.
Why it's wrong here
The SendEmailV2 action in the Office 365 Outlook connector is not deprecated and remains fully supported in Azure Logic Apps and Sentinel playbooks. Even if an action were deprecated, the playbook would still be invoked and would fail later during the action execution, not silently skip execution entirely. Therefore, deprecation does not explain why the automation rule cannot trigger the playbook.
- ✓
The playbook uses a recurrence trigger instead of a Microsoft Sentinel trigger.
Why this is correct
This is correct because automation rules require a playbook to start with a Microsoft Sentinel trigger (such as 'When Incident Created or Updated') to receive the incident payload. A recurrence trigger runs on a fixed schedule and does not accept any incident-specific parameters, so the automation rule cannot pass the incident ARM ID or properties to the playbook. As a result, the rule's action to run the playbook either fails validation or the playbook runs without the necessary incident context.
- ✗
The connection name 'office365' is incorrect.
Why it's wrong here
The connection name 'office365' is a standard, valid reference to the Office 365 Outlook API connection within the Logic Apps workflow. An incorrect connection name would cause the email action to fail at runtime with an authentication or error when sending, but the playbook itself would still be triggered by the automation rule. Since the playbook never receives the incident context, the connection name is not the root cause.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.