Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your SOC wants every new Microsoft Sentinel incident to automatically trigger a Logic Apps playbook that posts the incident details to a Microsoft Teams channel. You open the Logic Apps designer to create the playbook that will later be attached to an automation rule in Microsoft Sentinel. Which trigger must you choose as the playbook's first step so the playbook is available for selection in an incident-level automation rule?
Azure Event Grid trigger - When a resource event occurs
Recurrence trigger (schedule)
Azure Sentinel trigger - When an Azure Sentinel incident is created (Preview)
Azure Sentinel trigger - When a response to an Azure Sentinel alert is triggered
Automation rules in Microsoft Sentinel can run playbooks automatically when an incident is created only if the playbook's workflow begins with the dedicated incident trigger that the Microsoft Sentinel Logic Apps connector provides. The trigger called When an Azure Sentinel incident is created (Preview) (also shown in the connector as Microsoft Sentinel Incident - When incident creation rule was triggered) is recognized by Sentinel as an incident-level playbook and therefore appears in the automation-rule picker. Triggers meant for alert-level workflows (such as When a response to an Azure Sentinel alert is triggered) or generic triggers (Event Grid or Recurrence) are not displayed in the incident automation-rule blade because they do not operate on incident objects.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a playbook in Microsoft Sentinel?
Open an interactive chat with Bash
What is a Logic Apps trigger and how does it work in Microsoft Sentinel?
Open an interactive chat with Bash
What is the difference between an incident-level and alert-level playbook in Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .