Courseiva

Which Tools Can Trigger Automated Responses in Microsoft Sentinel

Your organization uses Microsoft Sentinel to monitor security events. You need to configure automated response actions for incidents. Which TWO of the following can be used to trigger automated responses in Microsoft Sentinel?

Quick Answer

The answer is Playbooks (Azure Logic Apps) and Automation rules. Playbooks are automated workflows built on Azure Logic Apps that can be triggered directly from analytics rules to orchestrate response actions like blocking IPs or isolating users, while Automation rules centrally manage and automate incident handling tasks such as assigning ownership or running playbooks at scale. On the AZ-500 exam, this question tests your ability to distinguish between Sentinel’s automation components and its passive tools—a common trap is confusing Workbooks (visual dashboards) or Watchlists (data references) with active response mechanisms. Remember that Playbooks execute specific logic, Automation rules orchestrate the process, and everything else is just data or display. A quick memory tip: if it doesn’t take action, it’s not automation—think “Playbooks play, Rules rule, everything else just shows or stores.”

⚠ Common exam trap

Many candidates confuse Workbooks or Hunting queries as automation triggers because they are interactive tools, but they lack the event-driven trigger capability that Automation rules and Playbooks provide.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automation rules

Automation rules in Microsoft Sentinel allow you to define automated responses that trigger when an incident is created or updated, based on conditions like severity or specific analytics rules. They can run playbooks (Azure Logic Apps) to execute complex workflows, such as sending notifications or creating tickets, without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Workbooks

    Why it's wrong here

    Workbooks are Azure Monitor visualisation canvases for dashboards and reports; they display data but create no incidents. Automation rules and playbooks execute response actions when incidents or alerts are raised, so workbooks serve reporting rather than automated remediation.

  • ✗

    Watchlists

    Why it's wrong here

    Watchlists supply reference data, such as VIP lists or IP ranges, that analytics rules can join against; they generate no incidents themselves. Automation rules and playbooks fire on incident or alert creation, so watchlists support enrichment rather than triggering automated response actions.

  • ✗

    Hunting queries

    Why it's wrong here

    Hunting queries run on demand in Logs to explore data; they produce results, not incident-triggered automation. Automation rules and playbooks respond to incidents or alerts, whereas hunting queries suit proactive threat hunting rather than automated response.

  • ✓

    Automation rules

    Why this is correct

    Automation rules run independently of playbooks and can trigger responses directly when an incident is created, satisfying the requirement for automated response actions. They support conditions on analytics rules, severity, and entity mappings, and can execute playbooks, assign owners, or change status without manual intervention.

  • ✓

    Playbooks (Azure Logic Apps)

    Why this is correct

    Playbooks are Logic Apps workflows that Microsoft Sentinel triggers from an incident or alert, executing the automated response actions. They satisfy the requirement for automated response by running the defined remediation logic against the incident.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-500

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Sentinel to manage security incidents. You need to configure automated response to block a user account when a high-severity incident is triggered. The response should be automatically executed when the incident is created. What should you create?

hard
  • A.An analytics rule
  • B.A playbook
  • ✓ C.An automation rule that triggers a playbook
  • D.A workbook

Why C: Automation rules in Microsoft Sentinel allow you to define automated responses that trigger when an incident is created, including running a playbook to block a user account. This directly meets the requirement for an automatic response upon incident creation without manual intervention.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.