Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

You are a security engineer at a company that uses Microsoft Sentinel. You need to create an automation rule that assigns a specific owner to incidents generated from a particular analytics rule and adds a comment. The automation rule must run when an incident is created. What should you use to define the condition?

⚠ Common exam trap

Watch out — candidates often confuse automation rules with playbooks; automation rules define conditions and basic actions, while playbooks are for complex workflows triggered by automation rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A Microsoft Sentinel automation rule with a condition based on the analytics rule name.

Microsoft Sentinel automation rules are designed to automate incident handling. They can trigger on incident creation and evaluate conditions such as the analytics rule name. When the condition matches, the rule can assign an owner and add a comment. Playbooks are for more complex orchestration and are invoked by automation rules, but the condition and simple actions are defined in the automation rule itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A playbook that uses the incident creation trigger and a condition action.

    Why it's wrong here

    Playbooks are Azure Logic Apps that can be triggered by incidents, but they are not used to define the initial condition for assigning owners and comments in the automation rule itself. While a playbook could perform these actions, it would need to be invoked by an automation rule, and the condition would still be defined in the automation rule. Playbooks are better suited for complex workflows.

  • ✗

    A workbook that monitors incident metrics and triggers an alert.

    Why it's wrong here

    Workbooks are for visualization and reporting, not for automating incident response. They cannot assign owners or add comments to incidents. Workbooks display data but do not take action. Therefore, they are not suitable for this scenario.

  • ✓

    A Microsoft Sentinel automation rule with a condition based on the analytics rule name.

    Why this is correct

    Automation rules in Microsoft Sentinel can trigger on incident creation and evaluate conditions such as the analytics rule name, severity, or tags. They can then assign an owner and add a comment. This directly meets the requirement to assign a specific owner and add a comment when an incident is created from a particular analytics rule.

  • ✗

    A Microsoft Sentinel analytics rule with incident grouping enabled.

    Why it's wrong here

    Analytics rules generate incidents but do not assign owners or add comments. Incident grouping only merges related alerts into a single incident. It cannot perform post-creation actions like assigning an owner or adding a comment. Automation rules are the correct feature for orchestrating such response actions based on incident properties.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.