Courseiva

AZ-500 Manage identity and access Practice Question

An analyst creates a Sentinel automation rule and a playbook. The playbook should run only when incidents are created from a specific analytics rule and severity is High. Where should this filtering be configured?

⚠ Common exam trap

Many candidates confuse automation rule conditions with analytics rule suppression or Logic App triggers, mistakenly thinking filtering should be done at the analytics rule or Logic App level rather than in the automation rule that orchestrates the playbook execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automation rule conditions

Automation rules in Microsoft Sentinel are designed to trigger actions based on incident creation or update events. By configuring conditions within the automation rule, you can specify that the associated playbook should only run when the incident is created from a specific analytics rule and has a severity of High. This is the correct and intended location for such filtering, as automation rules evaluate conditions before invoking the playbook.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Automation rule conditions

    Why this is correct

    Automation rule conditions are the correct answer because Microsoft Sentinel automation rules evaluate real-time alert or incident attributes—such as severity, status, entity types, and custom property values—against defined conditions. Only when every condition is satisfied does the rule invoke the linked Logic App playbook, providing precise, context-aware automation. This is exactly how Sentinel is designed to conditionally run playbooks, unlike the other options.

  • ✗

    Logic App recurrence trigger

    Why it's wrong here

    A Logic App recurrence trigger is time-based, running the playbook on a fixed schedule (for example, every 15 minutes or daily) rather than in response to an alert or incident being created. Because it never checks the alert's attributes at creation time, it would execute the playbook regardless of whether the event meets your required conditions, and it lacks the alert context that automation-rule conditions can evaluate. Therefore, it cannot target only the alerts you want to act on.

  • ✗

    Log Analytics workspace retention settings

    Why it's wrong here

    Log Analytics workspace retention settings only control how long ingested logs are stored in the workspace (ranging from 30 days to two years, or per-table retention policies). They have no interaction with Sentinel's automation rule processing and cannot evaluate an alert's severity, entities, or correlation rules. Changing retention might affect historical hunting or compliance, but it does not influence what triggers a playbook.

  • ✗

    Analytics rule suppression only

    Why it's wrong here

    Analytics rule suppression is a configuration that stops an analytics rule from generating duplicate alerts for the same entity within a specified time window (for example, suppressing re-alerts on the same user or IP for 4 hours). This only reduces alert noise; it does not provide condition-based branching for playbook execution, nor does it evaluate per-alert context to decide which playbook to run. Suppression happens before alert creation, whereas automation rule conditions run after an alert is created and control action execution.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.