Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium

A security operations center (SOC) manager is designing a new incident response workflow in Microsoft Sentinel. The manager wants to ensure that specific types of incidents, such as those related to critical infrastructure, are automatically assigned to a specialized Tier 2 team and have their severity escalated to 'High' immediately upon creation. Which Microsoft Sentinel feature provides the most efficient way to implement this automated workflow step?

  1. AHunting Queries
  2. BAutomation Rules with Playbooks
  3. CWorkbooks
  4. DAnalytics Rules
Show answer & explanation

Correct answer: B. Automation Rules with Playbooks

Automation Rules, when combined with Playbooks (Logic Apps), allow for complex, conditional automation of incident management tasks, including assigning incidents to specific teams and escalating severity, immediately upon creation.

Why the other options are wrong

  • A. Hunting Queries are for proactive threat discovery, not for automated incident response processes.
  • C. Workbooks are for visualization and reporting, not for automated incident response actions.
  • D. Analytics Rules generate incidents based on detections but do not directly manage incident workflow post-creation.

Microsoft Sentinel Automation Rules & Playbooks

Automation Rules in Sentinel can trigger Playbooks (Logic Apps) to perform complex, multi-step automated actions on incidents, such as enrichment, notification, assignment, and status updates.

  • Automation Rules act as triggers for Playbooks.
  • Playbooks (Logic Apps) execute the actual workflow.
  • Enables advanced, conditional incident response automation.

Memory trick: Rules Run Playbooks for Incident Control

More Mitigate threats using Microsoft Sentinel questions