nerdexam
Microsoft

SC-200 · Question #87

You are configuring Azure Sentinel. You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel. Which two actions…

The correct answer is B. Associate a playbook to the analytics rule that triggered the incident. D. Add a playbook. You need the playbook to be created first then associated. https://docs.microsoft.com/en-us/azure/sentinel/automate-responses-with-playbooks

Submitted by manish99· Apr 18, 2026Manage incident response

Question

You are configuring Azure Sentinel. You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel. Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AEnable Entity behavior analytics.
  • BAssociate a playbook to the analytics rule that triggered the incident.
  • CEnable the Fusion rule.
  • DAdd a playbook.
  • ECreate a workbook.

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    74% (14)
  • C
    5% (1)
  • E
    16% (3)

Explanation

You need the playbook to be created first then associated. https://docs.microsoft.com/en-us/azure/sentinel/automate-responses-with-playbooks

Topics

#Azure Sentinel#Playbooks#Incident Automation#Microsoft Teams Integration

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice