Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security operations team uses Microsoft Sentinel for SIEM. They want to automate the response to a high-severity alert indicating a brute-force attack against an Azure Active Directory user. The desired automated action is to block the compromised user account. Which Sentinel feature should they configure to achieve this automation?

  1. AHunting queries
  2. BWatchlists
  3. CAnalytics rules
  4. DPlaybooks
Show answer & explanation

Correct answer: D. Playbooks

Playbooks in Microsoft Sentinel are automated response procedures built on Azure Logic Apps. They can be triggered by alerts to perform actions like blocking user accounts, isolating machines, or sending notifications, making them suitable for automated incident response.

Why the other options are wrong

  • A. Hunting queries are used for proactive threat hunting, not automated response.
  • B. Watchlists are used for correlation and enrichment of data, not for automated response actions.
  • C. Analytics rules detect threats and generate alerts, but they do not automatically perform response actions.

Sentinel Playbook

An automated, predefined response procedure in Microsoft Sentinel, powered by Azure Logic Apps, that can be triggered by alerts or incidents to perform remediation actions.

  • Built using Azure Logic Apps.
  • Executes automated actions like blocking users, isolating hosts, sending emails.
  • Can be attached to analytics rules or run manually from incidents.

Memory trick: Playbooks Orchestrate the Security Dance.

More Manage security operations questions