New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft SC-200 Exam - Topic 5 Question 54 Discussion

Actual exam question for Microsoft's SC-200 exam
Question #: 54
Topic #: 5
[All SC-200 Questions]

You have an Azure subscription that contains an Microsoft Sentinel workspace.

You need to create a playbook that will run automatically in response to an Microsoft Sentinel alert.

What should you create first?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Tijuana
3 months ago
Surprised no one mentioned triggers in Azure Functions!
upvoted 0 times
...
Altha
4 months ago
A hunting query? That doesn't sound right.
upvoted 0 times
...
Holley
4 months ago
Wait, I thought it was an automation rule?
upvoted 0 times
...
Helaine
4 months ago
Totally agree, B is the way to go.
upvoted 0 times
...
Deonna
4 months ago
You need to create an Azure logic app first!
upvoted 0 times
...
Joni
4 months ago
I thought we might need a trigger in Azure Functions, but now I'm questioning if that's necessary before setting up the logic app.
upvoted 0 times
...
Juan
5 months ago
I practiced a similar question, and I feel like the logic app is definitely involved, but I can't recall if it's the very first thing we create.
upvoted 0 times
...
Stephaine
5 months ago
I'm not entirely sure, but I remember something about automation rules being important in Sentinel. Could that be the first step?
upvoted 0 times
...
Cheryll
5 months ago
I think we need to create an Azure logic app first, right? That seems to be the starting point for automating responses.
upvoted 0 times
...
Tamra
5 months ago
The CRL check is a smart move. If the certificate has been revoked, that would explain why the signing is failing even though it works on the website.
upvoted 0 times
...
Martin
5 months ago
Ah, I remember this from the CCNP ENCOR material. The routing protocol that requires a separate process per VRF is BGP. The other options like OSPF and EIGRP can use a single process across multiple VRFs.
upvoted 0 times
...
Devorah
5 months ago
I feel like "Capacity Management" covers the overall process, but does it really focus on monitoring and corrective actions? I could be mixing it up.
upvoted 0 times
...

Save Cancel