Microsoft Security Operations Analyst Associate SC-200 Practice Question
After reviewing an incident in Microsoft Sentinel, you conclude that it is an active attack. You need Sentinel to automatically run a Logic App playbook that disables the compromised Azure AD account whenever an incident changes to Active and its severity is High. You want the automation to occur without analyst interaction and with minimal delay. What should you configure?
Use Microsoft 365 Defender advanced hunting to run a live response action when the query matches the user account.
Attach the playbook to the analytics rule that generated the alerts as an alert automation action.
Add the playbook as a manual action button on the incident page for analysts to run when needed.
Create an automation rule that is triggered on incident updates, scoped to status Active and severity High, and add the playbook as an action.
Automation rules are evaluated automatically whenever an incident is created or updated. A rule can be scoped to specific incident properties, including status and severity, and can run one or more Logic App playbooks as soon as the trigger conditions are met. Attaching a playbook to an analytics rule fires per alert, not per incident, and cannot evaluate the incident status. Manually running a playbook requires analyst action, and Microsoft 365 Defender live response actions are not part of Microsoft Sentinel incident automation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an automation rule in Microsoft Sentinel?
Open an interactive chat with Bash
How do Logic App playbooks work in Microsoft Sentinel?
Open an interactive chat with Bash
Why are analytics rule playbooks different from automation rule playbooks in Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .