You have an Azure Sentinel workspace and need to automate responses to threats detected by Azure Sentinel. What should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Monitor workbooks.
Why this is the answer
Azure Monitor workbooks are incorrect because they are interactive reports that visualize data, not automate responses. Adaptive network hardening and adaptive application controls are features within Azure Security Center designed to reduce the attack surface of VMs by recommending network security group rules and controlling application execution, respectively. They are not used for automating responses within Azure Sentinel. Azure Service Health provides personalized guidance and support when Azure service issues affect you, but it does not automate threat responses. The correct tool for automating responses to threats detected by Azure Sentinel is Azure Logic Apps, often integrated as 'playbooks' within Sentinel. Logic Apps allow you to define automated workflows that can take actions like isolating compromised hosts, blocking malicious IPs, or creating incident tickets.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed