Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security operations center (SOC) team uses Microsoft Sentinel for threat detection and response. They want to ensure that all security incidents generated by Sentinel are automatically forwarded to their existing third-party ITSM (IT Service Management) system for ticketing and workflow management. Which Sentinel feature should they configure to achieve this automation?

  1. APlaybooks
  2. BWorkbooks
  3. CHunting Queries
  4. DAnalytic Rules
Show answer & explanation

Correct answer: A. Playbooks

Playbooks in Microsoft Sentinel are automated response procedures built on Azure Logic Apps. They can be triggered by incidents and perform actions like sending data to external systems.

Why the other options are wrong

  • B. Workbooks provide visualizations and dashboards for data, not automation for external systems.
  • C. Hunting Queries are for proactive threat hunting, not automated incident response.
  • D. Analytic Rules detect threats and generate incidents, but do not automate external forwarding.

Microsoft Sentinel Playbooks

Microsoft Sentinel Playbooks are automated, orchestrated, and customizable response procedures (Azure Logic Apps) that can be triggered by incidents or alerts.

  • Built on Azure Logic Apps.
  • Automate security operations tasks.
  • Can interact with other Azure services and external systems via connectors.

Memory trick: Playbooks perform the 'plays' to automate actions.

More Manage security operations questions