Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium
A company is using Microsoft Sentinel for SIEM and SOAR. They have configured analytic rules to detect suspicious activities. They now want to automatically enrich incidents with threat intelligence data from a third-party feed and then send a notification to a Microsoft Teams channel. Which type of automated response should they implement?
- APlaybooks
- BAutomation Rules
- CHunting Queries
- DWorkbooks
Show answer & explanationAnswer & explanation
Correct answer: A. Playbooks
Playbooks (Azure Logic Apps) are used in Sentinel for complex automated responses, including integrating with external services like threat intelligence feeds and sending notifications to platforms like Microsoft Teams.
Why the other options are wrong
- B. Automation Rules are for basic incident management tasks (e.g., assigning owner, changing status) or triggering playbooks, but not for direct external integrations and complex logic.
- C. Hunting Queries are for proactive threat discovery, not automated incident response.
- D. Workbooks are for data visualization, not for automated actions.
Sentinel Playbooks for SOAR
Microsoft Sentinel Playbooks, powered by Azure Logic Apps, enable Security Orchestration, Automation, and Response (SOAR) by automating complex workflows, integrating with external systems, and performing actions based on incidents.
- Built on Azure Logic Apps.
- Automate incident response and enrichment.
- Connect to external services via connectors.
- Can be triggered by incidents or alerts.
Memory trick: Playbooks orchestrate complex 'plays' for SOAR.