Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender XDR and Microsoft Sentinel. You need to ensure that high-severity incidents are automatically escalated to the on-call security engineer via Microsoft Teams. Which three components should you configure?

⚠ Common exam trap

Many candidates confuse analytics rules with automation rules, thinking an analytics rule can directly send Teams messages, when in fact analytics rules only generate alerts and require a separate automation rule and playbook to perform actions like messaging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A playbook that uses a condition to check severity and then sends a Teams message.

A playbook in Microsoft Sentinel can contain a condition action that evaluates the incident severity. If the severity is 'High', the playbook then uses a Microsoft Teams connector to send a message to the on-call security engineer, automating the escalation process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A playbook that uses a condition to check severity and then sends a Teams message.

    Why this is correct

    A Microsoft Sentinel playbook is an Azure Logic Apps workflow that can inspect an incident's properties, such as severity, using a condition action. Once the condition evaluates that the severity meets the threshold, a subsequent action using the Teams connector posts the message to the specified channel. This is correct because playbooks are the automation components that run conditional logic and initiate external actions.

  • ✓

    An automation rule in Microsoft Sentinel that triggers on incident creation with high severity.

    Why this is correct

    An automation rule in Microsoft Sentinel operates when an incident is created or updated, and you can specify conditions that must be satisfied, for example severity equals High. When those conditions match, the rule can execute a playbook as an action, effectively triggering the automated workflow. This is a valid way to automate the initial response to high-severity incidents.

  • ✓

    A Microsoft Teams connector in the playbook to post a message to a channel.

    Why this is correct

    For the playbook to deliver a notification, it must include a Microsoft Teams connector action that sends a message to a channel. The connector handles authentication to Microsoft Teams and provides the necessary API operation to post the content. This is correct because without the connector, the playbook would have no means to communicate with Teams.

  • ✗

    An analytics rule that sends a Teams message when a high-severity alert fires.

    Why it's wrong here

    Analytics rules are responsible for querying data at regular intervals and generating alerts, but they do not contain actions to send messages or call external systems directly. When an analytics rule fires, it creates an incident within Microsoft Sentinel, and further automation must be handled by automation rules or playbooks. Therefore, this option incorrectly assigns a direct messaging capability to analytics rules.

  • ✗

    A workbook that displays high-severity incidents for manual escalation.

    Why it's wrong here

    Workbooks in Microsoft Sentinel are interactive dashboards that render data from queries and provide visual insight, but they are not designed to initiate any workflows. Displaying high-severity incidents in a workbook would require a human operator to manually escalate by reviewing the data and taking action. This option lacks automation and hence is incorrect for automated escalation.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.