SC-100 · Question #117
Draga and Drop Question Your client has implemented Microsoft Sentinel as its cloud-based Security Information and Event Management (SIEM). The client wants to maximize the value of their investment…
The correct answer is Playbook; Workbook; Notebook. The question tests the ability to correctly map specific Microsoft Sentinel tools (Playbook, Workbook, Notebook) to their appropriate functions within the security incident management lifecycle, demonstrating knowledge of their roles in automation, visualization, and advanced…
Question
Exhibits
Answer Area
Drag items
Correct arrangement
- Playbook
- Workbook
- Notebook
Explanation
The question tests the ability to correctly map specific Microsoft Sentinel tools (Playbook, Workbook, Notebook) to their appropriate functions within the security incident management lifecycle, demonstrating knowledge of their roles in automation, visualization, and advanced threat analysis.
Approach. The correct interaction involves dragging the appropriate Sentinel tool to each activity based on its primary function:
- 'Automatically isolate an infected machine.' should be matched with 'Playbook'. In Microsoft Sentinel, Playbooks are based on Azure Logic Apps and are used for Security Orchestration, Automation, and Response (SOAR). They automate responses to security incidents and alerts, such as isolating a machine, blocking an IP, or sending notifications.
- 'Visualize and monitor threat data.' should be matched with 'Workbook'. Microsoft Sentinel Workbooks (based on Azure Workbooks) are interactive dashboards that allow users to create custom visualizations, reports, and monitoring views of security data to gain insights into threats and incidents.
- 'Analyze data with Python machine learning.' should be matched with 'Notebook'. Microsoft Sentinel Notebooks (based on Jupyter notebooks) provide a powerful environment for advanced threat hunting, data analysis, and the application of machine learning using Python scripts. They allow security analysts to perform complex investigations that go beyond standard queries.
Common mistakes.
- common_mistake. A common mistake is confusing 'Playbook' with 'Runbook'. While both are automation tools, 'Playbook' (built on Azure Logic Apps) is the primary and purpose-built tool within Microsoft Sentinel for automated incident response and SOAR actions like isolating machines. 'Runbook' (from Azure Automation) is a more general-purpose automation tool, often used for infrastructure management or broader IT automation, and is not directly integrated into Sentinel for automated incident response in the same way Playbooks are. Using 'Notebook' or 'Playbook' for visualization is incorrect because 'Workbook' is specifically designed for creating interactive dashboards and reports. Similarly, using 'Playbook' or 'Workbook' for advanced Python-based data analysis and machine learning is incorrect, as 'Notebook' is the dedicated tool for this purpose.
Concept tested. This question tests the candidate's understanding of the core components and capabilities of Microsoft Sentinel, specifically its Security Orchestration, Automation, and Response (SOAR) features (Playbooks), data visualization and reporting tools (Workbooks), and advanced threat hunting and analytical capabilities (Notebooks). It assesses the ability to identify the correct tool for specific security operations within the incident management lifecycle.
Topics
Community Discussion
No community discussion yet for this question.

