AZ-500 Manage identity and access Practice Question
A security team uses Microsoft Sentinel. They have created a playbook in Azure Logic Apps that automatically isolates a compromised VM by modifying a network security group. They want the playbook to run automatically whenever an incident of type 'VM Isolation' is created. Which Microsoft Sentinel feature should they use to trigger the playbook automatically?
⚠ Common exam trap
Candidates often confuse automation rules with analytics rules, thinking that a scheduled query rule is needed to trigger a playbook, but automation rules are the dedicated feature for incident-based automation without requiring a separate alert generation rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automation rules.
Automation rules in Microsoft Sentinel are designed to trigger automated responses, such as running a playbook, when an incident is created or updated. In this scenario, the rule can be configured to match incidents of type 'VM Isolation' and automatically execute the Logic Apps playbook to isolate the compromised VM. This is the correct feature for incident-triggered automation without requiring a separate analytics rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automation rules.
Why this is correct
Automation rules are the correct mechanism in Microsoft Sentinel for incident-centric orchestration. They allow you to define trigger conditions based on incident properties such as severity, status, title, or tactic, and then run playbooks, change incident status, assign ownership, add tasks, or apply tags whenever an incident is created or updated. This provides a single, consistent automation pipeline for incident management rather than tying actions to the specific detection that generated the alert.
- ✗
Scheduled analytics rules.
Why it's wrong here
Scheduled analytics rules run KQL queries on a defined frequency and produce alerts when the results match a threshold. While you can attach playbooks to the alert-creation step through alert automation or by configuring incident creation in the rule, these rules themselves do not trigger on incident creation or update—they only generate the raw alerts that may later be converted into incidents. Incident-level automation, especially on updates, requires an automation rule rather than a scheduled query rule.
- ✗
Fusion rules.
Why it's wrong here
Fusion rules are a type of advanced multi-stage attack detection that uses machine learning to correlate low-fidelity alerts from Microsoft 365 Defender, Defender for Cloud, and other sources into a single high-fidelity incident. These rules are purely detection logic and cannot invoke playbooks; at most, they cause an incident to be created, and any subsequent automated response must be handled by an automation rule scoped to incident creation or update. Recognizing the separation between detection (Fusion) and response (automation rules) is essential for designing Sentinel SOAR workflows.
- ✗
Workbooks.
Why it's wrong here
Workbooks are Azure Monitor-based interactive reports and dashboards that display data stored in the Sentinel Log Analytics workspace. They provide visualizations, filters, and drill-downs for security analysis and hunting, but they have no execution context or trigger mechanism to run playbooks, modify incidents, or otherwise automate response actions. They are purely observational tooling, so they cannot fulfill the role of automation rules in any incident-response process.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.