Which Tools Can Trigger Automated Responses in Microsoft Sentinel
Your organization uses Microsoft Sentinel to monitor security events. You need to configure automated response actions for incidents. Which TWO of the following can be used to trigger automated responses in Microsoft Sentinel?
Quick Answer
The answer is Playbooks (Azure Logic Apps) and Automation rules. Playbooks are automated workflows built on Azure Logic Apps that can be triggered directly from analytics rules to orchestrate response actions like blocking IPs or isolating users, while Automation rules centrally manage and automate incident handling tasks such as assigning ownership or running playbooks at scale. On the AZ-500 exam, this question tests your ability to distinguish between Sentinel’s automation components and its passive tools—a common trap is confusing Workbooks (visual dashboards) or Watchlists (data references) with active response mechanisms. Remember that Playbooks execute specific logic, Automation rules orchestrate the process, and everything else is just data or display. A quick memory tip: if it doesn’t take action, it’s not automation—think “Playbooks play, Rules rule, everything else just shows or stores.”
⚠ Common exam trap
Many candidates confuse Workbooks or Hunting queries as automation triggers because they are interactive tools, but they lack the event-driven trigger capability that Automation rules and Playbooks provide.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automation rules
Automation rules in Microsoft Sentinel allow you to define automated responses that trigger when an incident is created or updated, based on conditions like severity or specific analytics rules. They can run playbooks (Azure Logic Apps) to execute complex workflows, such as sending notifications or creating tickets, without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Workbooks
Why it's wrong here
Workbooks are Azure Monitor visualisation canvases for dashboards and reports; they display data but create no incidents. Automation rules and playbooks execute response actions when incidents or alerts are raised, so workbooks serve reporting rather than automated remediation.
- ✗
Watchlists
Why it's wrong here
Watchlists supply reference data, such as VIP lists or IP ranges, that analytics rules can join against; they generate no incidents themselves. Automation rules and playbooks fire on incident or alert creation, so watchlists support enrichment rather than triggering automated response actions.
- ✗
Hunting queries
Why it's wrong here
Hunting queries run on demand in Logs to explore data; they produce results, not incident-triggered automation. Automation rules and playbooks respond to incidents or alerts, whereas hunting queries suit proactive threat hunting rather than automated response.
- ✓
Automation rules
Why this is correct
Automation rules run independently of playbooks and can trigger responses directly when an incident is created, satisfying the requirement for automated response actions. They support conditions on analytics rules, severity, and entity mappings, and can execute playbooks, assign owners, or change status without manual intervention.
- ✓
Playbooks (Azure Logic Apps)
Why this is correct
Playbooks are Logic Apps workflows that Microsoft Sentinel triggers from an incident or alert, executing the automated response actions. They satisfy the requirement for automated response by running the defined remediation logic against the incident.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-500
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Sentinel to manage security incidents. You need to configure automated response to block a user account when a high-severity incident is triggered. The response should be automatically executed when the incident is created. What should you create?
hard- A.An analytics rule
- B.A playbook
- ✓ C.An automation rule that triggers a playbook
- D.A workbook
Why C: Automation rules in Microsoft Sentinel allow you to define automated responses that trigger when an incident is created, including running a playbook to block a user account. This directly meets the requirement for an automatic response upon incident creation without manual intervention.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.