Free Microsoft Cybersecurity SC-100 Actual Exam Questions - Question 9 Discussion

Question No. 9
Your company is moving all on-premises workloads to Azure and Microsoft 365. You need to design a
security orchestration, automation, and response (SOAR) strategy in Microsoft Sentinel that meets
the following requirements:
• Minimizes manual intervention by security operation analysts
• Supports Waging alerts within Microsoft Teams channels
What should you include in the strategy?
Select one option, then reveal solution.
US
RL
Ryan L.
2026-02-12

It’s B for sure. Playbooks handle automation and can send alerts straight to Teams, which cuts down manual work. Data connectors and KQL don’t automate or push notifications by themselves.

0
AG
Ahmed G.
2026-02-11

B/D? Playbooks (B) are the obvious choice for automation and Teams integration, but KQL (D) is essential for querying and defining the alerts that trigger these playbooks. Without well-crafted queries, the automation won’t know what to act on. So you kinda need both to build a solid SOAR strategy that cuts down manual work and supports Teams notifications effectively. Data connectors just bring in data, and workbooks only help visualize, so they don’t really address the automation or Teams alerting parts directly.

0
AG
Ahmed G.
2026-01-22

B/C? Playbooks definitely handle automation and Teams notifications, but workbooks could help visualize alerts too. Still, automation means playbooks are the main fit here.

0
AG
Ahmed G.
2026-01-16

Option B, playbooks automate and send alerts directly to Teams channels.

0
SB
Sam B.
2026-01-15

B for sure, playbooks automate tasks and integrate with Teams.

0