"Playbooks in Azure Sentinel are based on workflows built in Azure Logic Apps, a cloud service that helps you schedule, automate, and orchestrate tasks and workflows across systems throughout the enterprise. This means that playbooks can take advantage of all the power and customizability of Logic Apps' built-in templates."
Explanation: Azure Sentinel is a cloud-native SIEM (Security Information and Event Management) system that provides intelligent security analytics and threat intelligence across the enterprise. Sentinel livestreams allow security teams to create real-time, continuous monitoring streams that can be used to detect and respond to active attacks immediately. This feature is specifically designed for active monitoring and rapid response, making it the best fit for the requirement to "rapidly remediate active attacks."
Yes, active attack but also says to remediate rapidly. So how do you do that? Using automation - that’s Playbooks
upvoted 2 times
...
...
This section is not available anymore. Please use the main Exam Page.SC-200 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Eltooth
Highly Voted 3 years, 7 months agoRamye
1 year, 2 months agoAlaReAla
Highly Voted 3 years, 7 months agog_man_rap
Most Recent 8 months, 1 week agochepeerick
1 year, 6 months agoLion007
2 years, 10 months agoFllinstone
3 years, 6 months agoLafsa
2 years, 4 months agoJens128
3 years, 3 months agoRamye
1 year, 2 months ago