Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your company is using Microsoft Sentinel to monitor security events. You need to ensure that all incidents generated in Sentinel are automatically sent to a third-party ticketing system via a webhook. Which Sentinel feature should you configure?

⚠ Common exam trap

Many candidates confuse inbound data ingestion (data connectors) with outbound event-driven automation (automation rules + playbooks), leading candidates to incorrectly select a data connector for exporting incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule that runs a playbook when an incident is created.

Automation rules in Microsoft Sentinel can trigger a playbook (an Azure Logic Apps workflow) when an incident is created. The playbook can then use an HTTP action to call a webhook endpoint on the third-party ticketing system, sending the incident data automatically. This is the native, built-in mechanism for outbound event-driven integration with external systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an automation rule that runs a playbook when an incident is created.

    Why this is correct

    Automation rules in Microsoft Sentinel are condition-based triggers that fire on incident creation, and they can invoke a playbook (an Azure Logic Apps workflow). The playbook can use an HTTP or webhook action to create a ticket in your external ticketing system, making this the correct outbound integration path. Unlike the other options, this is an active, automated mechanism that sends data out of Sentinel.

  • ✗

    Use a watchlist to map incidents to ticketing system IDs.

    Why it's wrong here

    Watchlists in Sentinel are local reference data sets (CSV or JSON) used within KQL queries for enriching detections, such as joining on IP addresses or account names. They are passive, query-time lookup tables and have no built-in capability to initiate outbound actions or API calls. Mapping incident IDs to ticket IDs in a watchlist would only allow Sentinel to correlate data you manually place there; it cannot deliver that data to a ticketing system or trigger any workflow.

  • ✗

    Create a workbook that exports incidents to the ticketing system.

    Why it's wrong here

    Workbooks are interactive dashboards built on KQL queries, designed for visualizing and analyzing Sentinel data. They are rendered in the Azure portal and, while they can show incident details and even include 'Export to Excel' or similar UI actions, they are not an automation or integration service. A workbook cannot push incidents or events to an external ticketing system because it lacks outbound connectors and runs only when a user opens it, not in response to incident creation.

  • ✗

    Configure a data connector to the ticketing system.

    Why it's wrong here

    A data connector in Sentinel is an ingestion pipeline that pulls logs and alerts from external sources (such as Microsoft Entra ID, Azure Activity, or third-party products) into the workspace. The data flow is strictly inbound into Sentinel; connectors do not send data back out. Configuring a ticketing system data connector would import ticket-related logs into Sentinel for analysis, not export Sentinel incidents to that ticketing system, so it cannot solve the outbound integration requirement.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.