SC-200 Practice Question 3769

Exam: SC-200
Domain: Respond to security incidents
Difficulty: medium
A SOC team wants Microsoft Sentinel to automatically post an adaptive card alert into a dedicated Microsoft Teams channel whenever an incident with Critical severity is created. What feature facilitates this?

Answer Options

A
An Automation Rule that runs a Playbook posting an adaptive card to Teams
B
A manual email sent by a junior security analyst
C
A scheduled PowerShell script running on a client machine
D
An SMS alert configured in the domain registrar portal

Correct Answer

A: An Automation Rule that runs a Playbook posting an adaptive card to Teams

Explanation

An Automation Rule configured to trigger on Incident creation that runs a Playbook (Azure Logic App) containing the "Post adaptive card in a chat or channel" action.