SC-200 · Question #121
You have an Azure subscription that uses Microsoft Sentinel. You need to minimize the administrative effort required to respond to the incidents and remediate the security threats detected by…
The correct answer is C. Microsoft Sentinel automation rules D. Microsoft Sentinel playbooks. Microsoft Sentinel's Automation rules can be used to automatically trigger actions or playbooks in response to detected security incidents. This reduces the need for manual intervention and minimizes administrative effort. Playbooks in Microsoft Sentinel can be used to automate…
Question
You have an Azure subscription that uses Microsoft Sentinel. You need to minimize the administrative effort required to respond to the incidents and remediate the security threats detected by Microsoft Sentinel. Which two features should you use? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Options
- AMicrosoft Sentinel bookmarks
- BAzure Automation runbooks
- CMicrosoft Sentinel automation rules
- DMicrosoft Sentinel playbooks
- EAzure Functions apps
How the community answered
(33 responses)- A3% (1)
- B9% (3)
- C85% (28)
- E3% (1)
Explanation
Microsoft Sentinel's Automation rules can be used to automatically trigger actions or playbooks in response to detected security incidents. This reduces the need for manual intervention and minimizes administrative effort. Playbooks in Microsoft Sentinel can be used to automate incident response tasks and remediation steps, such as quarantining an affected machine or disabling a compromised account. This allows you to quickly and consistently take action on security incidents, further reducing administrative effort.
Topics
Community Discussion
No community discussion yet for this question.