Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft SC-200 Exam - Topic 4 Question 111 Discussion

You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually.You deploy Azure Sentinel.You need to use the existing logic app as a playbook in Azure Sentinel. What should you do first?
D) Modify the trigger in the logic app.
A) And a new scheduled query rule.
B) Add a data connector to Azure Sentinel.
C) Configure a custom Threat Intelligence connector in Azure Sentinel.

Microsoft SC-200 Exam - Topic 4 Question 111 Discussion

Actual exam question for Microsoft's SC-200 exam
Question #: 111
Topic #: 4
[All SC-200 Questions]

You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually.

You deploy Azure Sentinel.

You need to use the existing logic app as a playbook in Azure Sentinel. What should you do first?

Show Suggested Answer Hide Answer
Suggested Answer: D

In Microsoft Sentinel, playbooks are Azure Logic Apps that automate responses to alerts or incidents. To use an existing Logic App as a playbook in Sentinel, it must start with the ''Microsoft Sentinel alert'' trigger. This trigger allows Sentinel to call and pass alert details to the Logic App automatically.

When an existing Logic App has a manual trigger, it cannot be invoked directly by Sentinel. Therefore, the first step is to modify the trigger to replace the manual trigger with the ''When a response to an Azure Sentinel alert is triggered'' trigger. After that, you can link it within Sentinel incidents or automation rules.

This process is detailed in Microsoft Defender XDR and Sentinel documentation under ''Connect a Logic App to Sentinel as a playbook.''

Hence, the correct answer is D. Modify the trigger in the logic app.


Contribute your Thoughts:

0/2000 characters
Glynda
4 days ago
Exactly, then we can integrate it smoothly.
upvoted 0 times
...
Roxane
9 days ago
Right, focus on the trigger first!
upvoted 0 times
...
Lizbeth
14 days ago
Adding a scheduled query rule could be useful too, but later.
upvoted 0 times
...
Tyra
19 days ago
I agree, the trigger needs to be compatible.
upvoted 0 times
...
Jordan
25 days ago
I feel like modifying the trigger is the most straightforward step.
upvoted 0 times
...
Willard
30 days ago
But what about adding a data connector first?
upvoted 0 times
...
Roxane
1 month ago
Yeah, that makes sense. It needs to work with Sentinel.
upvoted 0 times
...
Glynda
1 month ago
I think we should modify the trigger in the logic app.
upvoted 0 times
...
Tora
2 months ago
D is definitely the right choice, no doubt about it!
upvoted 0 times
...
Laquanda
2 months ago
Surprised that no one mentioned the scheduled query rule!
upvoted 0 times
...
Shalon
2 months ago
Wait, isn't it better to add a data connector first?
upvoted 0 times
...
Jutta
2 months ago
I agree, D makes the most sense here!
upvoted 0 times
...
Aileen
2 months ago
You need to modify the trigger in the logic app first.
upvoted 0 times
...
Staci
2 months ago
I’m leaning towards adding a new scheduled query rule, but I feel like I need to double-check how that fits with the logic app.
upvoted 0 times
...
Juliana
3 months ago
This question feels similar to one we practiced about playbooks, but I can't recall if we had to configure a custom Threat Intelligence connector.
upvoted 0 times
...
Maryann
3 months ago
I remember something about data connectors being important for integrating services, so maybe we should add a data connector to Azure Sentinel?
upvoted 0 times
...
Dorsey
3 months ago
I think we might need to modify the trigger in the logic app first, but I'm not entirely sure if that's the right step.
upvoted 0 times
...

Save Cancel