Microsoft Certified: Azure Security Engineer AssociateManage security operationsHard

A security operations team uses Microsoft Sentinel. They have configured several analytic rules that generate incidents. The team observes that a significant number of low-fidelity incidents are being created, which are often benign but require manual review, leading to alert fatigue. They want to automatically close these low-fidelity incidents if they meet specific criteria (e.g., source IP is from an allow-list, or the alert name contains 'informational'). What Microsoft Sentinel feature should they use to achieve this automation?

  1. AAutomation Rules
  2. BWorkbooks
  3. CHunting Queries
  4. DThreat Intelligence
Show answer & explanation

Correct answer: A. Automation Rules

Automation Rules in Microsoft Sentinel allow you to automatically perform actions on incidents, such as changing their status (e.g., closing them), assigning owners, or triggering playbooks, based on predefined conditions. This is perfect for reducing alert fatigue by automating the handling of low-fidelity or benign incidents.

Why the other options are wrong

  • B. Workbooks are used for data visualization and dashboards, not for automating actions on incidents.
  • C. Hunting Queries are used for proactive threat hunting, not for automating incident response or management.
  • D. Threat Intelligence is used to enrich incident data with known threat indicators, not for automating incident management actions.

Microsoft Sentinel Automation Rules

Rules in Microsoft Sentinel that automatically execute actions on incidents or alerts based on predefined conditions.

  • Automate incident triage, assignment, and closure.
  • Can trigger playbooks for more complex automation.
  • Help reduce alert fatigue and improve SOC efficiency.

Memory trick: Automation rules 'rule' over how incidents 'flow'.

More Manage security operations questions