AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You are configuring Microsoft Sentinel to use a playbook for automated response to incidents. The playbook needs to block the source IP address of a malicious sign-in on the Azure Firewall. Which Microsoft Sentinel feature should the playbook use?
⚠ Common exam trap
Test-takers frequently confuse Azure Automation runbooks (Option A) with Logic Apps because both can automate tasks, but Sentinel playbooks are explicitly built on Logic Apps, not Automation runbooks, and the exam tests this specific architectural distinction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Logic Apps
Microsoft Sentinel playbooks are built on Azure Logic Apps, which provide the workflow automation and connectors needed to orchestrate response actions like blocking an IP on Azure Firewall. Logic Apps can integrate with Azure Firewall via its REST API or the Azure Resource Manager connector to update firewall rules, making it the correct feature for this automated incident response task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Automation runbooks
Why it's wrong here
Azure Automation runbooks are designed for administrative configuration and patch management using PowerShell or Python runbooks. They lack the event-driven trigger types and connector library needed to respond directly to Sentinel incidents and alerts. Sentinel playbooks require Logic Apps, which provide the native integration with Microsoft security services. Runbooks can be called from Logic Apps, but they are not the playbook engine itself.
- ✗
Azure Functions
Why it's wrong here
Azure Functions are serverless, code-first processes that can execute custom logic, but they do not provide the managed workflow engine that Sentinel playbooks need. A playbook is specifically a Logic Apps workflow with built-in connectors and visual orchestration; Functions can be embedded as an action within a Logic App, yet they cannot serve as the playbook container. Sentinel automation rules invoke Logic Apps directly, not Functions.
- ✓
Azure Logic Apps
Why this is correct
Azure Logic Apps are the correct platform for Sentinel playbooks because they provide a low-code workflow engine with native connectors to Microsoft Defender, Teams, ServiceNow, and hundreds of other services. Logic Apps are triggered by Sentinel incidents and alerts through dedicated connectors, allowing automated investigation and response actions. They support both consumption and standard hosting plans and are the only compute service that integrates natively with Sentinel automation rules.
- ✗
KQL queries
Why it's wrong here
KQL (Kusto Query Language) is used to search, filter, and aggregate log data in Azure Sentinel and Log Analytics, not to execute automated response workflows. While KQL queries power analytics rules and hunting, they cannot trigger actions like opening a ticket or blocking an IP address. Playbooks perform those actions through Logic Apps, making KQL fundamentally unsuitable as an automation engine.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.