In an Azure Sentinel workspace, which two events can trigger a playbook?
Choose an answer
Tap an option to check your answer.
Correct answer: An Azure Sentinel alert is generated., An Azure Sentinel incident is created..
Why this is the answer
Azure Sentinel playbooks, which are automated response procedures built on Azure Logic Apps, can be triggered by two primary events. First, when an Azure Sentinel alert is generated, a playbook can be configured to run automatically. This allows for immediate action, such as isolating a compromised host or enriching alert data. Second, when an Azure Sentinel incident is created, a playbook can also be initiated. Incidents aggregate related alerts, and triggering a playbook at this stage enables more comprehensive responses, like creating a ticket in a service management system or notifying security teams. Incorrect options: An Azure Sentinel scheduled query rule being executed does not directly trigger a playbook; rather, if that rule generates an alert, then the alert can trigger the playbook. Adding an Azure Sentinel data connector is a configuration step and not an event that triggers automated responses. An Azure Sentinel hunting query result being returned is part of proactive threat hunting and doesn't inherently trigger an automated playbook response, though a hunting query could lead to the manual creation of an incident or alert.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed