AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You are a security engineer managing a Microsoft Sentinel workspace. The security operations team wants to automatically create a ServiceNow incident whenever a new high-severity incident is generated in Microsoft Sentinel. You need to configure the automation rule to trigger only for incidents with severity High and to include the incident's entities in the ServiceNow ticket. What should you do first?
⚠ Common exam trap
It's easy for candidates to confuse the direction of the ServiceNow connector: it ingests ServiceNow data into Sentinel, not the reverse; outbound automation requires playbooks triggered by automation rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a playbook that uses the ServiceNow connector, then create an automation rule with the condition Severity equals High and add an action to run the playbook.
Automation rules in Microsoft Sentinel allow you to define conditions and actions that run when incidents are created or updated. To integrate with ServiceNow, you must first create a playbook that contains the logic to create a ServiceNow incident, using the ServiceNow connector. Then, you create an automation rule that triggers on High severity incidents and runs that playbook. This ensures that only high-severity incidents result in ServiceNow tickets, and the playbook can access incident entities to populate the ticket details.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the Microsoft Sentinel data connector for ServiceNow and configure the connector to automatically create incidents for all high-severity alerts.
Why it's wrong here
The ServiceNow data connector in Microsoft Sentinel is used to ingest ServiceNow records into Sentinel, not to create ServiceNow incidents from Sentinel incidents. It works in the opposite direction. There is no built-in configuration in the connector to automatically create incidents based on severity. Automation rules and playbooks are the correct mechanism for outbound actions to ServiceNow.
- ✗
Create an analytics rule that generates an incident and configure its incident settings to run a playbook automatically.
Why it's wrong here
Analytics rules can be configured to run playbooks on incident creation, but they do not provide the flexibility to filter by severity after incident creation. The requirement is to trigger only for high-severity incidents, which is better handled by an automation rule that evaluates incident properties. Also, the question asks for the first step, and creating an analytics rule is not necessary if the incident is already generated.
- ✓
Create a playbook that uses the ServiceNow connector, then create an automation rule with the condition Severity equals High and add an action to run the playbook.
Why this is correct
Automation rules in Microsoft Sentinel can trigger playbooks based on incident conditions. The playbook must be created first, then referenced in the automation rule. The condition Severity equals High ensures only high-severity incidents trigger the playbook, and the playbook can access incident entities to populate ServiceNow fields. This is the correct sequence to achieve the requirement.
- ✗
Create a workbook that monitors incidents and use Azure Logic Apps to send an email to the security team when a high-severity incident occurs.
Why it's wrong here
Workbooks are for visualization and reporting, not for automation. They cannot trigger actions like creating a ServiceNow incident. While Logic Apps can be used, the question specifically requires integration with Microsoft Sentinel's automation capabilities, and workbooks do not provide a mechanism to trigger playbooks based on incident severity. This approach would not meet the automated ticketing requirement.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.