Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft AZ-500 Exam - Topic 1 Question 105 Discussion

You have an Azure subscription that contains a Microsoft Sentinel workspace named Sentinel 1. Sentinel! is NOT onboarded to the unified security operations platform in Microsoft 365.You need to create a new playbook in Sentinel 1. The solution must support the use of automation rules.Which type of playbook should you create?
D) a playbook with an incident trigger or an alert trigger
A) a playbook with an incident trigger only
B) a playbook with an alert trigger only
C) a playbook with an entity trigger only
E) a playbook with an alert trigger or an entity trigger

Microsoft AZ-500 Exam - Topic 1 Question 105 Discussion

Actual exam question for Microsoft's AZ-500 exam
Question #: 105
Topic #: 1
[All AZ-500 Questions]

You have an Azure subscription that contains a Microsoft Sentinel workspace named Sentinel 1. Sentinel! is NOT onboarded to the unified security operations platform in Microsoft 365.

You need to create a new playbook in Sentinel 1. The solution must support the use of automation rules.

Which type of playbook should you create?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Yolande
3 days ago
I thought entity triggers could work too?
upvoted 0 times
...
Felicitas
8 days ago
Definitely D! That’s the way to go.
upvoted 0 times
...
Celestina
13 days ago
You need an incident or alert trigger for automation rules.
upvoted 0 times
...
Lorean
18 days ago
I recall that entity triggers are less common in this context. I’m leaning towards D as well, but I’m not completely confident.
upvoted 0 times
...
Berry
23 days ago
I practiced a similar question, and I feel like the incident trigger is crucial. Could it be A, or is it really D that covers both?
upvoted 0 times
...
Valda
29 days ago
I'm not entirely sure, but I remember something about alert triggers being more common for automation. Maybe B is the right choice?
upvoted 0 times
...
Avery
1 month ago
I think the playbook needs to support automation rules, so it might be D, since it mentions both incident and alert triggers.
upvoted 0 times
...

Save Cancel