Your team wants high-severity “Impossible travel” incidents to automatically disable the affected user in Microsoft Entra ID, add the source IP to a Sentinel watchlist, and post a message to a SOC Microsoft Teams channel. You will use a Logic App playbook with a managed identity. What two actions should you perform?
Choose an answer
Tap an option to check your answer.
Correct answer: Build a Logic App playbook using the Microsoft Sentinel incident trigger, enable a system-assigned managed identity, and grant it Entra ID User Administrator and Microsoft Sentinel Contributor permissions., Create a Microsoft Sentinel automation rule that filters on Severity = High and Title contains "Impossible travel" and runs the playbook..
Why this is the answer
To automate the response, you need a Logic App playbook triggered by Sentinel incidents. The playbook requires a system-assigned managed identity for secure authentication, and this identity needs specific permissions: Entra ID User Administrator to disable users and Microsoft Sentinel Contributor to add entries to watchlists. An automation rule in Sentinel is then configured to detect "Impossible travel" incidents with high severity and execute the created playbook. Incorrect options: An Azure Monitor action group is used for alerts from Azure Monitor, not directly for Sentinel incident automation. Assigning the Owner role at the subscription root is excessive and violates the principle of least privilege. The managed identity only needs specific permissions for the tasks it performs. Both Consumption and Standard Logic Apps can be triggered by Sentinel. The need for a Standard Logic App is not indicated by the requirements.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed