nerdexam
Microsoft

AZ-500 · Question #580

You onboard Microsoft Sentinel. You connect Microsoft Sentinel to Microsoft Defender for Cloud. You need to automate the mitigation of incidents in Microsoft Sentinel. The solution must minimize…

The correct answer is A. a playbook. A playbook is a collection of response and remediation actions and logic that can be run from Microsoft Sentinel as a routine. A playbook can: Help automate and orchestrate your threat response Integrate with other systems, both internal and external Be configured to run…

Submitted by carter_n· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

You onboard Microsoft Sentinel. You connect Microsoft Sentinel to Microsoft Defender for Cloud. You need to automate the mitigation of incidents in Microsoft Sentinel. The solution must minimize administrative effort. What should you create?

Options

  • Aa playbook
  • Ba function app
  • Can alert rule
  • Da runbook

How the community answered

(44 responses)
  • A
    89% (39)
  • B
    2% (1)
  • C
    2% (1)
  • D
    7% (3)

Explanation

A playbook is a collection of response and remediation actions and logic that can be run from Microsoft Sentinel as a routine. A playbook can: Help automate and orchestrate your threat response Integrate with other systems, both internal and external Be configured to run automatically in response to specific alerts or incidents, or run manually on- demand, such as in response to new alerts https://learn.microsoft.com/en-us/azure/sentinel/automation/automation

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice