Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium

A security operations team is configuring Microsoft Sentinel to automatically enrich incidents with additional context from an external vulnerability management system. This enrichment should involve querying the external system for details about affected assets and adding those details as comments to the Sentinel incident. Which Microsoft Sentinel feature, combined with an Azure Logic App, is best suited to achieve this automated enrichment?

  1. AWorkbooks
  2. BAnalytics rules
  3. CPlaybooks
  4. DHunting queries
Show answer & explanation

Correct answer: C. Playbooks

Playbooks in Microsoft Sentinel are powered by Azure Logic Apps and are designed for automated incident response and enrichment. They can connect to external systems, retrieve data, and update Sentinel incidents, perfectly matching the requirement for querying a vulnerability management system and adding details to an incident.

Why the other options are wrong

  • A. Workbooks are for data visualization and reporting, not for automated actions or external system integration.
  • B. Analytics rules are for detection and incident creation, not for automated post-creation enrichment.
  • D. Hunting queries are for proactive threat discovery, not for automated incident response actions.

Microsoft Sentinel Playbooks (Logic Apps)

Microsoft Sentinel playbooks are automated, scalable, cloud-native workflows powered by Azure Logic Apps that can be triggered by Sentinel incidents or alerts to perform response and enrichment actions.

  • Built on Azure Logic Apps.
  • Automate repetitive security tasks.
  • Can interact with various internal and external services.

Memory trick: Playbooks: Play Your Part in Automating Enrichment!

More Mitigate threats using Microsoft Sentinel questions