nerdexam
Microsoft

SC-200 · Question #29

You are configuring Azure Sentinel. You need to send a Microsoft Teams message to a channel whenever a sign-in from a suspicious IP address is detected. Which two actions should you perform in Azure…

The correct answer is A. Add a playbook. B. Associate a playbook to an incident. To automatically send a Microsoft Teams message when a suspicious sign-in is detected, two steps are required. First, you must Add a playbook (A) - a playbook is an Azure Logic App that contains the automation logic, including a Teams 'Post a message' action. Second, you must…

Submitted by omar99· Apr 18, 2026Detect and remediate threats using Microsoft Sentinel

Question

You are configuring Azure Sentinel. You need to send a Microsoft Teams message to a channel whenever a sign-in from a suspicious IP address is detected. Which two actions should you perform in Azure Sentinel?Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AAdd a playbook.
  • BAssociate a playbook to an incident.
  • CEnable Entity behavior analytics.
  • DCreate a workbook.
  • EEnable the Fusion rule.

How the community answered

(20 responses)
  • A
    75% (15)
  • C
    15% (3)
  • D
    5% (1)
  • E
    5% (1)

Explanation

To automatically send a Microsoft Teams message when a suspicious sign-in is detected, two steps are required. First, you must Add a playbook (A) - a playbook is an Azure Logic App that contains the automation logic, including a Teams 'Post a message' action. Second, you must Associate the playbook to an incident (B) - this links the playbook to the relevant analytics rule or alert so it triggers automatically when the condition is met. Entity behavior analytics (C) helps detect anomalies but does not send notifications on its own. A workbook (D) is for visualization only. The Fusion rule (E) detects multi-stage attacks but does not drive notification workflows.

Topics

#Azure Sentinel#Playbooks#Automation#Incident Response

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice