Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Which TWO are benefits of using Microsoft Sentinel's automation rules? (Choose two.)

⚠ Common exam trap

Test-takers frequently confuse automation rules with analytics rules or playbooks, mistakenly thinking automation rules can create rules or query external feeds, when in fact automation rules only respond to incidents with predefined actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Trigger a playbook when an incident is created or updated.

Option D is correct because Microsoft Sentinel automation rules can define conditions (such as incident creation or update) and then invoke a playbook (Logic App) as the action, enabling automated response workflows. Option E is correct because automation rules support an 'Assign owner' action, letting you automatically route incidents to a specific analyst or team based on rule conditions. Options A, B, and C are not benefits of automation rules: incident aggregation/merging is handled by the incident merging feature rather than automation rules, analytics rules are created manually or via templates/API rather than generated from incident patterns by automation rules, and querying external threat intelligence feeds is performed through threat intelligence connectors, watchlists, or analytics rule queries, not automation rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Aggregate multiple incidents into a single incident.

    Why it's wrong here

    Microsoft Sentinel automation rules operate on a single incident at a time and do not merge or aggregate incidents. Incident grouping is configured in the analytics rule's alert grouping settings, where multiple alerts can produce one incident, but that occurs before automation rules run. Automation rules can change severity, add tags, assign owners, or invoke playbooks, but combining separate incidents is not one of their built-in actions.

  • ✗

    Create new analytics rules based on incident patterns.

    Why it's wrong here

    Automation rules are response-oriented; they lack any action that generates or modifies analytics rules. Analytics rules are defined separately in the Analytics blade or via APIs, and their detection logic is not influenced by automation rules. While a playbook invoked by an automation rule could call the API to create a new analytics rule, that is an indirect effect of a Logic App, not a native automation-rule capability.

  • ✗

    Automatically query external threat intelligence feeds.

    Why it's wrong here

    Automation rules do not contain a native action to query external threat intelligence feeds. Threat intelligence ingestion is handled by data connectors or TAXII feeders, and lookups are typically performed via watchlists, threat-intelligence indicators, or playbook steps in Logic Apps. An automation rule could trigger a playbook that queries a feed, but the rule itself only provides the trigger and condition evaluation; it does not perform the feed query.

  • ✓

    Trigger a playbook when an incident is created or updated.

    Why this is correct

    A primary benefit of automation rules is the 'Run playbook' action, which can be triggered automatically when an incident is created or updated. This enables incident response teams to execute Logic Apps that perform enrichment, containment, or remediation steps without manual intervention. Playbooks can be invoked with the incident as context, making it easy to gather data, block indicators, or send notifications.

  • ✓

    Automatically assign incidents to a specific analyst or team.

    Why this is correct

    Automation rules can automatically assign incidents to a specific analyst or team via the 'Assign owner' action. The assignment can be based on conditions like severity, tactic, or custom properties, ensuring high-priority incidents reach the right personnel immediately. This reduces response time and helps enforce ownership policies across the SOC, as the owner can be set to a user principal name or a Microsoft Entra ID group.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.