AZ-500 · Question #580
You onboard Microsoft Sentinel. You connect Microsoft Sentinel to Microsoft Defender for Cloud. You need to automate the mitigation of incidents in Microsoft Sentinel. The solution must minimize…
The correct answer is A. a playbook. A playbook is a collection of response and remediation actions and logic that can be run from Microsoft Sentinel as a routine. A playbook can: Help automate and orchestrate your threat response Integrate with other systems, both internal and external Be configured to run…
Question
Options
- Aa playbook
- Ba function app
- Can alert rule
- Da runbook
How the community answered
(44 responses)- A89% (39)
- B2% (1)
- C2% (1)
- D7% (3)
Explanation
A playbook is a collection of response and remediation actions and logic that can be run from Microsoft Sentinel as a routine. A playbook can: Help automate and orchestrate your threat response Integrate with other systems, both internal and external Be configured to run automatically in response to specific alerts or incidents, or run manually on- demand, such as in response to new alerts https://learn.microsoft.com/en-us/azure/sentinel/automation/automation
Community Discussion
No community discussion yet for this question.