Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage a Microsoft Sentinel workspace. Whenever a new incident is generated by the HighCPUUsage analytics rule, you must immediately run an existing Logic App playbook named CPUMitigate and mark the incident with the tag autoMitigated. Analysts must see the updated incident status and tag before they start triage. Which configuration should you implement?
Configure an Azure Monitor action group to trigger the CPUMitigate Logic App through a webhook whenever a High CPU metric alert fires.
Attach the CPUMitigate playbook to the HighCPUUsage analytics rule by selecting the Alert automation tab, so the playbook runs whenever an alert is generated.
Deploy an Azure Automation runbook that polls Sentinel incidents every minute and, when it finds a HighCPUUsage incident, invokes CPUMitigate and adds the tag.
Create an automation rule with order set to 1 that triggers when an incident from the HighCPUUsage analytics rule is created, runs the CPUMitigate playbook, and adds the autoMitigated tag.
Automation rules in Microsoft Sentinel are evaluated the moment an incident is created or updated. By setting the rule's order value to 1 (the lowest possible), you ensure it runs before any other automation or manual action. Within the rule you can scope the condition to incidents originating from the HighCPUUsage analytics rule, specify the trigger When incident is created, call the CPUMitigate playbook, and add or update the autoMitigated tag. Alert-level playbook attachments, Azure Automation runbooks that poll, or Azure Monitor action groups either act on alerts rather than incidents, rely on periodic polling, or operate outside Sentinel, so they cannot guarantee the immediate, incident-level enrichment required.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an automation rule in Microsoft Sentinel?
Open an interactive chat with Bash
What is a Logic App playbook and how is it used in Microsoft Sentinel?
Open an interactive chat with Bash
Why is setting the automation rule's order important in Azure Sentinel?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .