Courseiva

AZ-500 Playbook trigger Practice Question

Which THREE are valid ways to trigger a playbook in Microsoft Sentinel? (Choose three.)

⚠ Common exam trap

A common mistake is confusing automation rule triggers: remember that automation rules can trigger on both alert creation and incident creation, but not on watchlist updates or entity page actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Manually from an incident by selecting 'Run playbook'.

Option A is correct because Microsoft Sentinel allows analysts to manually trigger a playbook directly from an incident's page by selecting 'Run playbook', which executes the associated Logic App workflow on demand. Option B is correct because automation rules in Microsoft Sentinel can be configured with a trigger of 'When incident is created' and an action of 'Run playbook', automatically invoking the playbook as soon as the incident is generated. Option E is correct because automation rules also support the trigger 'When alert is created', allowing a playbook to be run automatically at alert creation time, before or independently of incident creation. Option C is not a valid trigger because watchlists are reference data sources and do not have automation-rule triggers for playbook execution. Option D is not a valid trigger because the 'Investigate' action on an entity page opens the investigation experience and does not itself run a playbook.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Manually from an incident by selecting 'Run playbook'.

    Why this is correct

    From an incident, clicking 'Run playbook' opens a side panel where you can select an enabled playbook, which then executes with the Incident trigger. This manual trigger is essential for ad-hoc response, testing, or remediation tasks that require human judgment, and it passes the full incident context—including alerts, entities, and metadata—to the playbook. It is a valid, documented way to launch a playbook on demand.

  • ✓

    From an automation rule when an incident is created.

    Why this is correct

    Automation rules can also execute a playbook when an incident is created, using the Incident trigger, which fires on the consolidated incident object rather than on the underlying alerts. This allows centralized orchestration for triage, classification, assignment, and enrichment across all alerts that make up the incident. It is distinct from the alert-created trigger because the playbook receives the incident-level context and runs once per incident.

  • ✗

    From a watchlist item update.

    Why it's wrong here

    A watchlist item update is a data-plane operation that modifies a reference table used for correlation and enrichment, so it does not generate a security alert or incident. Microsoft Sentinel playbooks are triggered only through automation rules on alert/incident creation, manual invocation from an incident, or direct logic app triggers; there is no built-in trigger that fires on watchlist changes. Therefore, updating a watchlist item cannot initiate a playbook.

  • ✗

    From an entity page by clicking 'Investigate'.

    Why it's wrong here

    The 'Investigate' button on an entity page opens the investigation graph, which is an interactive visualization tool for exploring relationships between entities and alerts. It does not invoke a playbook; playbooks require an explicit trigger such as an automation rule, manual 'Run playbook' action, or a direct Logic App webhook. No automation connector is bound to the Investigate action, so this is not a valid triggering method.

  • ✓

    From an automation rule when an alert is created.

    Why this is correct

    Automation rules in Microsoft Sentinel can trigger a playbook when an alert is created by setting the rule's action to 'Run playbook' and selecting a playbook with the Alert trigger. This trigger fires for each individual alert generated by analytics rules, providing immediate, automated response before or during incident creation. It is a primary method for scaling alert-based orchestration without manual intervention.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.