Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelEasy
A security operations center (SOC) manager wants to implement a solution in Microsoft Sentinel that automatically triages low-severity incidents by closing them if they remain unresolved for more than 48 hours and have no associated comments. Which Microsoft Sentinel feature should the SOC manager configure?
- AAutomation rules
- BPlaybooks
- CAnalytics rules
- DHunting queries
Show answer & explanationAnswer & explanation
Correct answer: A. Automation rules
Automation rules in Microsoft Sentinel are designed to automatically perform actions on incidents, such as changing their status, assigning ownership, or running playbooks, based on specific conditions.
Why the other options are wrong
- B. Playbooks (Azure Logic Apps) can be triggered by automation rules for more complex, multi-step actions, but automation rules themselves handle the conditional triage logic.
- C. Analytics rules are used for detecting threats and generating incidents, not for incident triage actions.
- D. Hunting queries are used for proactive threat discovery, not for automated incident management.
Microsoft Sentinel Automation Rules
Automation rules in Microsoft Sentinel allow you to automatically perform actions on incidents when they are created or updated, based on defined conditions.
- Automate incident management tasks.
- Apply to incidents created or updated.
- Can trigger playbooks for complex workflows.
Memory trick: Auto-triage bots handle low-priority alerts, keeping the SOC clean.