Your organization uses Microsoft Sentinel. An incident is created for a possible data exfiltration via an unapproved external IP address. Which type of Microsoft Sentinel automation should you use to automatically block the IP address in the firewall?
Playbooks are Logic Apps triggered by Microsoft Sentinel automation rules, enabling an automated response that calls firewall APIs to block the IP. This satisfies the requirement to block the unapproved external address automatically upon incident creation.
Why this answer
Playbooks in Microsoft Sentinel are automated workflows based on Azure Logic Apps that can perform response actions, such as blocking an IP address in a firewall. When an incident indicates data exfiltration via an unapproved external IP, a playbook can be triggered automatically or manually to execute the block action via integration with firewall APIs or management tools.
Exam trap
The SC-200 exam often tests the distinction between detection (analytics rules) and response (playbooks), so candidates may confuse an analytics rule's ability to generate alerts with the capability to perform automated remediation actions.
How to eliminate wrong answers
Option A is wrong because a data connector is used to ingest logs and events from various sources into Sentinel, not to perform automated response actions like blocking an IP. Option B is wrong because an analytics rule generates alerts or incidents based on query logic; it does not execute remediation actions such as firewall changes. Option C is wrong because a watchlist is a collection of data (e.g., known malicious IPs) for correlation in queries, but it cannot directly trigger a block action in a firewall.