Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium

A security operations center (SOC) team needs to automate their response to common security incidents, such as blocking IP addresses or isolating compromised devices, based on alerts generated by their security information and event management (SIEM) system. Which Microsoft security solution provides this automation capability?

  1. AMicrosoft Sentinel Playbooks
  2. BMicrosoft Intune
  3. CAzure AD Identity Protection
  4. DMicrosoft 365 Defender
Show answer & explanation

Correct answer: A. Microsoft Sentinel Playbooks

Microsoft Sentinel Playbooks, powered by Azure Logic Apps, enable security orchestration, automation, and automated response (SOAR) to security incidents.

Why the other options are wrong

  • B. Microsoft Intune manages endpoints and applications, not incident response automation.
  • C. Azure AD Identity Protection focuses on detecting and remediating identity-based risks.
  • D. Microsoft 365 Defender unifies protection across M365 services but doesn't primarily focus on SOAR capabilities for general SIEM alerts.

Microsoft Sentinel Playbooks

Automated response mechanisms within Microsoft Sentinel, powered by Azure Logic Apps, that execute predefined actions in response to security incidents or alerts.

  • Security Orchestration, Automation, Response (SOAR)
  • Powered by Azure Logic Apps
  • Automates incident response tasks

Memory trick: Sentinel's Playbooks orchestrate your automated security game.

More Describe the capabilities of Microsoft Security solutions questions