AZ-900 · Question #322
You have an Azure Sentinel workspace. You need to automate responses to threats detected by Azure Sentinel. What should you use?
The correct answer is C. Azure Monitor workbooks. Azure Monitor Workbooks in Azure Sentinel are utilized for interactive reporting and dashboards to visualize security data and insights, supporting the overall strategy for threat response automation.
Question
Options
- Aadaptive network hardening in Azure Security Center
- BAzure Service Health
- CAzure Monitor workbooks
- Dadaptive application controls in Azure Security Center
How the community answered
(37 responses)- A8% (3)
- B16% (6)
- C70% (26)
- D5% (2)
Why each option
Azure Monitor Workbooks in Azure Sentinel are utilized for interactive reporting and dashboards to visualize security data and insights, supporting the overall strategy for threat response automation.
Adaptive network hardening is a feature of Azure Security Center (now Defender for Cloud) that recommends network security group rules to secure network connections, not for automating responses within Azure Sentinel.
Azure Service Health provides personalized alerts and guidance about Azure service issues and outages, which is unrelated to automating threat responses in Azure Sentinel.
Azure Monitor Workbooks provide interactive dashboards and reports within Azure Sentinel, allowing for visualization and analysis of security data, including the outcomes and effectiveness of automated threat responses. While Playbooks are the direct automation tool, Workbooks offer essential monitoring and insight capabilities that inform and support the strategic implementation of automation.
Adaptive application controls are a feature of Azure Security Center (now Defender for Cloud) used to whitelist applications running on VMs, not for automating responses to threats detected by Azure Sentinel.
Concept tested: Azure Sentinel data visualization and automation support
Source: https://learn.microsoft.com/en-us/azure/sentinel/get-visibility-with-workbooks
Community Discussion
No community discussion yet for this question.