AZ-500 Manage identity and access • Set 11
AZ-500 Manage identity and access Practice Test 11 — 15 questions with explanations. Free, no signup.
A security operations team uses Microsoft Sentinel. They want to create an automation that automatically changes the severity of an incident from 'Medium' to 'High' when a specific indicator of compromise (IOC) is observed in the incident's entities. The playbook should run immediately when the incident is created. Which type of automation rule trigger should they configure?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.