You onboard Azure Sentinel and connect it to Azure Security Center. You want to automate mitigation of incidents while minimizing administrative effort. What should you create?
Choose an answer
Tap an option to check your answer.
Correct answer: a playbook.
Why this is the answer
A playbook in Azure Sentinel is an automated procedure that can be run in response to an incident. Playbooks are built on Azure Logic Apps and allow you to define a series of actions, such as isolating a compromised virtual machine, sending notifications, or updating incident tickets, thereby automating mitigation with minimal administrative effort. An alert rule defines the conditions for generating an alert but doesn't automate mitigation actions. A function app is a serverless compute service that can execute code, but it requires more manual configuration to integrate with Sentinel for incident response compared to a pre-built playbook. A runbook, typically associated with Azure Automation, can automate tasks but is not the primary or most integrated solution for automated incident response within Azure Sentinel.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed