Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium
A security operations center (SOC) team needs to streamline their threat response by automating repetitive tasks, such as blocking malicious IPs, isolating infected devices, and enriching incident data, directly from alerts generated by Microsoft 365 Defender and Microsoft Sentinel. Which capability within Microsoft Sentinel is designed for this automation?
- AThreat Intelligence
- BAnalytics Rules
- CPlaybooks
- DWorkbooks
Show answer & explanationAnswer & explanation
Correct answer: C. Playbooks
Microsoft Sentinel Playbooks (powered by Azure Logic Apps) are designed to automate and orchestrate security tasks. They can be triggered by alerts or incidents to perform actions like blocking IPs, isolating devices, or sending notifications, streamlining the incident response process (SOAR).
Why the other options are wrong
- A. Threat Intelligence is data about known threats, used to enhance detection, not to automate response directly.
- B. Analytics Rules are used for detecting threats and generating alerts, not for automated response actions.
- D. Workbooks provide interactive reports and dashboards for monitoring and visualization, not automation.
Microsoft Sentinel Playbooks
Automated, predefined response procedures in Microsoft Sentinel (powered by Azure Logic Apps) used to orchestrate and automate security tasks.
- Enable Security Orchestration, Automation, and Response (SOAR)
- Can be triggered by alerts or incidents
- Perform actions like blocking, isolating, enriching data, and notifying
Memory trick: Playbooks play out the security plan.