nerdexam
Microsoft

AZ-500 · Question #583

You have an Azure subscription that contains a Microsoft Sentinel workspace named Sentinel1. Sentinel1 is NOT onboarded to the Unified security operations platform in Microsoft 365. You need to…

The correct answer is D. a playbook with an incident trigger or an alert trigger. Since you're using this automation rule to run a playbook, select the Run playbook action from the drop-down list. You'll then be prompted to select from a second drop-down list that shows the available playbooks. An automation rule can run only those playbooks that start with…

Submitted by femi9· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

You have an Azure subscription that contains a Microsoft Sentinel workspace named Sentinel1. Sentinel1 is NOT onboarded to the Unified security operations platform in Microsoft 365. You need to create a new playbook in Sentinel1. The solution must support the use of automation rules. Which type of playbook should you create?

Options

  • Aa playbook with an incident trigger only
  • Ba playbook with an alert trigger only
  • Ca playbook with an entity trigger only
  • Da playbook with an incident trigger or an alert trigger
  • Ea playbook with an alert trigger or an entity trigger

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    4% (2)
  • D
    92% (44)

Explanation

Since you're using this automation rule to run a playbook, select the Run playbook action from the drop-down list. You'll then be prompted to select from a second drop-down list that shows the available playbooks. An automation rule can run only those playbooks that start with the same trigger (incident or alert) as the trigger defined in the rule, so only those playbooks appear in the https://learn.microsoft.com/en-us/azure/sentinel/automation/run-playbooks

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice