Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium

A security operations team wants to ensure that specific security incidents in Microsoft Sentinel are automatically assigned to a designated analyst and tagged with relevant information based on the incident's title and severity. Which Microsoft Sentinel feature should be used to achieve this automation?

  1. AHunting queries
  2. BPlaybooks
  3. CAutomation rules
  4. DWorkbooks
Show answer & explanation

Correct answer: C. Automation rules

Automation rules in Microsoft Sentinel allow you to define conditions based on incident properties (like title and severity) and then automatically perform actions such as assigning ownership and adding tags to the incident.

Why the other options are wrong

  • A. Hunting queries are used for proactive threat discovery, not for automated incident assignment or tagging.
  • B. Playbooks (Azure Logic Apps) can be triggered by automation rules for more complex, multi-step workflows, but the direct conditional assignment and tagging can be handled by automation rules themselves.
  • D. Workbooks are for data visualization and reporting, not for automating incident management tasks.

Microsoft Sentinel Automation Rules

Automation rules in Microsoft Sentinel allow you to automatically perform actions on incidents when they are created or updated, based on defined conditions such as incident title, severity, or associated entities.

  • Automate incident assignment and tagging.
  • Apply based on incident properties.
  • Can trigger playbooks for advanced tasks.

Memory trick: For 'Auto-Assigning' and 'Tagging' incidents, use 'Automation Rules'.

More Mitigate threats using Microsoft Sentinel questions