AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your organization wants to use Microsoft Sentinel to automatically respond to high-severity incidents. Which feature should you configure?
⚠ Common exam trap
It's easy for candidates to confuse analytics rules (which generate incidents) with automation rules (which respond to incidents), leading them to select Option A thinking severity configuration alone enables automated response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that triggers a playbook on incident creation.
Microsoft Sentinel automation rules allow you to define automated responses to incidents, such as triggering a playbook (a collection of actions based on Azure Logic Apps) when an incident is created. This directly meets the requirement to automatically respond to high-severity incidents without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an analytics rule with a high severity.
Why it's wrong here
Analytics rules in Microsoft Sentinel are detection mechanisms that query data and create alerts or incidents based on conditions. Setting a high severity only affects the incident's priority for triage; it does not trigger any automated response action. To automate remediation, the analytics rule must be paired with an automation rule that invokes a playbook, but the analytics rule itself is not capable of executing response steps.
- ✓
Create an automation rule that triggers a playbook on incident creation.
Why this is correct
Automation rules are the native orchestration component in Microsoft Sentinel for centrally managing incident responses. You can configure a trigger such as 'When incident is created' and conditionally invoke an Azure Logic Apps-based playbook to perform actions like opening a ticket, notifying analysts, or applying remediation. This directly achieves automated response because it links incident creation to an executable workflow without manual intervention.
- ✗
Create a workbook to visualize incidents.
Why it's wrong here
Workbooks are interactive dashboards built on Kusto query language (KQL) that visualize data such as incident trends, alert counts, and entity activities. They provide read-only reporting and monitoring views but cannot initiate any automated action or trigger a playbook. Since the requirement is to automate a response rather than display data, a workbook does not meet that need.
- ✗
Enable entity behavior analytics.
Why it's wrong here
Entity behavior analytics (EBA) in Sentinel uses machine learning to profile users, hosts, and other entities, detecting anomalous patterns and generating alerts for potential threats. It is a detection feature that improves alert quality and prioritization, but it does not itself execute any response actions. Any automation built on EBA outputs would still require separate automation rules and playbooks to be triggered.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.