SC-200 · Question #33
You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually. You deploy Azure Sentinel. You need to use the existing logic…
The correct answer is D. Modify the trigger in the logic app. For an Azure Logic App to function as a playbook in Azure Sentinel, it must use an Azure Sentinel-specific trigger - either 'When a response to an Azure Sentinel alert is triggered' or 'When Azure Sentinel incident creation rule was triggered'. The existing logic app uses a…
Question
You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually. You deploy Azure Sentinel. You need to use the existing logic app as a playbook in Azure Sentinel. What should you do first?
Options
- AAnd a new scheduled query rule.
- BAdd a data connector to Azure Sentinel.
- CConfigure a custom Threat Intelligence connector in Azure Sentinel.
- DModify the trigger in the logic app.
How the community answered
(15 responses)- A7% (1)
- C13% (2)
- D80% (12)
Explanation
For an Azure Logic App to function as a playbook in Azure Sentinel, it must use an Azure Sentinel-specific trigger - either 'When a response to an Azure Sentinel alert is triggered' or 'When Azure Sentinel incident creation rule was triggered'. The existing logic app uses a manual trigger, which Sentinel cannot invoke automatically. Therefore, the first step is to modify the trigger in the logic app to use one of the Sentinel triggers. Only after this change can the logic app be recognized and used as a playbook within Sentinel. Adding a scheduled query rule, data connector, or threat intelligence connector are not prerequisites for this.
Topics
Community Discussion
No community discussion yet for this question.