SC-200 · Question #87
You are configuring Azure Sentinel. You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel. Which two actions…
The correct answer is B. Associate a playbook to the analytics rule that triggered the incident. D. Add a playbook. You need the playbook to be created first then associated. https://docs.microsoft.com/en-us/azure/sentinel/automate-responses-with-playbooks
Question
You are configuring Azure Sentinel. You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel. Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Options
- AEnable Entity behavior analytics.
- BAssociate a playbook to the analytics rule that triggered the incident.
- CEnable the Fusion rule.
- DAdd a playbook.
- ECreate a workbook.
How the community answered
(19 responses)- A5% (1)
- B74% (14)
- C5% (1)
- E16% (3)
Explanation
You need the playbook to be created first then associated. https://docs.microsoft.com/en-us/azure/sentinel/automate-responses-with-playbooks
Topics
Community Discussion
No community discussion yet for this question.