Microsoft Certified: Azure Security Engineer AssociateManage security operationsEasy

A security operations team uses Microsoft Sentinel for threat detection and response. They have configured analytic rules to generate incidents based on suspicious activities. The team wants to ensure that critical incidents, specifically those related to 'High Severity Malware Detections' on production servers, trigger an immediate notification to the on-call security engineer via Microsoft Teams. Which feature in Microsoft Sentinel should be used to automate this notification?

  1. AHunting Queries
  2. BPlaybooks
  3. CWatchlists
  4. DWorkbooks
Show answer & explanation

Correct answer: B. Playbooks

Playbooks in Microsoft Sentinel are automated procedures that can be triggered by incidents or alerts. They integrate with various services, including Microsoft Teams, to perform actions like sending notifications, making them ideal for automated incident response.

Why the other options are wrong

  • A. Hunting Queries are used for proactive threat hunting, not for automated incident response.
  • C. Watchlists are used for correlation and enrichment of data, not for automated actions or notifications.
  • D. Workbooks are used for data visualization and dashboards, not for automated actions.

Microsoft Sentinel Playbooks

Automated procedures in Microsoft Sentinel that can be triggered by incidents or alerts to perform predefined actions.

  • Enable Security Orchestration, Automation, and Response (SOAR) capabilities.
  • Built on Azure Logic Apps.
  • Can integrate with various services for actions like notifications, blocking IPs, or creating tickets.

Memory trick: Playbooks 'play' out your response automatically.

More Manage security operations questions