nerdexam
Microsoft

AZ-900 · Question #322

You have an Azure Sentinel workspace. You need to automate responses to threats detected by Azure Sentinel. What should you use?

The correct answer is C. Azure Monitor workbooks. Azure Monitor Workbooks in Azure Sentinel are utilized for interactive reporting and dashboards to visualize security data and insights, supporting the overall strategy for threat response automation.

Submitted by fernanda_arg· Mar 5, 2026Describe Azure management and governance

Question

You have an Azure Sentinel workspace. You need to automate responses to threats detected by Azure Sentinel. What should you use?

Options

  • Aadaptive network hardening in Azure Security Center
  • BAzure Service Health
  • CAzure Monitor workbooks
  • Dadaptive application controls in Azure Security Center

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    16% (6)
  • C
    70% (26)
  • D
    5% (2)

Why each option

Azure Monitor Workbooks in Azure Sentinel are utilized for interactive reporting and dashboards to visualize security data and insights, supporting the overall strategy for threat response automation.

Aadaptive network hardening in Azure Security Center

Adaptive network hardening is a feature of Azure Security Center (now Defender for Cloud) that recommends network security group rules to secure network connections, not for automating responses within Azure Sentinel.

BAzure Service Health

Azure Service Health provides personalized alerts and guidance about Azure service issues and outages, which is unrelated to automating threat responses in Azure Sentinel.

CAzure Monitor workbooksCorrect

Azure Monitor Workbooks provide interactive dashboards and reports within Azure Sentinel, allowing for visualization and analysis of security data, including the outcomes and effectiveness of automated threat responses. While Playbooks are the direct automation tool, Workbooks offer essential monitoring and insight capabilities that inform and support the strategic implementation of automation.

Dadaptive application controls in Azure Security Center

Adaptive application controls are a feature of Azure Security Center (now Defender for Cloud) used to whitelist applications running on VMs, not for automating responses to threats detected by Azure Sentinel.

Concept tested: Azure Sentinel data visualization and automation support

Source: https://learn.microsoft.com/en-us/azure/sentinel/get-visibility-with-workbooks

Community Discussion

No community discussion yet for this question.

Full AZ-900 Practice