exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 64 discussion

Actual exam question from Microsoft's SC-200
Question #: 64
Topic #: 3
[All SC-200 Questions]

You have an Azure subscription that contains a Microsoft Sentinel workspace.

You need to create a playbook that will run automatically in response to a Microsoft Sentinel alert.

What should you create first?

  • A. a hunting query in Microsoft Sentinel
  • B. an Azure logic app
  • C. an automation rule in Microsoft Sentinel
  • D. a trigger in Azure Functions
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PhoenixSlasher
Highly Voted 2 years, 2 months ago
Selected Answer: B
Creating a logic app before creating the automation rule that triggers said logic app is ... logically the correct answer.
upvoted 9 times
...
user636
Most Recent 8 months ago
Selected Answer: B
The answer is B. You can create a Playbook in the automation blade of Sentinel. Also, when you are creating the playbook, as part of the process you will create a logic app. You do NOT need to create an automation rule for creating a playbook. The playbooks can run independent of the automation rule as well.
upvoted 1 times
...
DChilds
1 year ago
Selected Answer: C
First create the conditions to trigger the playbook so the selected answer of C should be the correct one. An automation rule is the first thing to create when needing to create a playbook, the automation rule will determine the conditions to be met before the playbook is triggered. Logic Apps is then used to configure the behavior of the playbook only after it has been triggered.
upvoted 1 times
...
Ramye
1 year, 1 month ago
Selected Answer: B
Confirmed by SC-200 Microsoft Practice Assessment https://learn.microsoft.com/en-us/credentials/certifications/exams/sc-200/practice/assessment?assessment-type=practice&assessmentId=59
upvoted 3 times
...
kazaki
1 year, 2 months ago
Selected Answer: C
All of comments are wrong First thing is creating the flow which will trigger the playbook https://learn.microsoft.com/en-us/azure/sentinel/automate-responses-with-playbooks?ssp=1&darkschemeovr=1&setlang=en&cc=EG&safesearch=moderate#steps-for-creating-a-playbook
upvoted 1 times
...
chepeerick
1 year, 5 months ago
Correct Option B
upvoted 1 times
...
emv
1 year, 7 months ago
Selected Answer: B
Playbooks in Azure Sentinel are created using Logic Apps. To create a new Logic App, click on "Playbooks" in the left-hand menu under "Configuration." Click the "+ Add" button to create a new playbook.
upvoted 1 times
...
billo79152718
1 year, 8 months ago
Selected Answer: B
B. an Azure logic app
upvoted 1 times
...
evilprime
2 years ago
i'd say from these answers, i think 'logic app' hunting query makes no sense, automation rule is dependent of a existing logic app, azure functions doesn't make sense.
upvoted 2 times
...
Cenos
2 years, 1 month ago
Selected Answer: B
Logic Apps are a dependency for creating a playbook
upvoted 3 times
...
antoniokt
2 years, 1 month ago
Selected Answer: B
B is correct
upvoted 2 times
...
[Removed]
2 years, 1 month ago
Selected Answer: B
Azure logic apps are a workflow automation platform that provides a visual designer to model and automate processes as a series of steps or actions. Logic apps can be triggered by events, such as an alert in Microsoft Sentinel, and can perform a variety of actions, such as sending an email or creating a work item in Azure DevOps.
upvoted 1 times
...
jwkin
2 years, 2 months ago
Selected Answer: B
First step in creating a new play book is Select Automation, select Create. https://learn.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook?tabs=LAC%2Cincidents
upvoted 1 times
jwkin
2 years, 2 months ago
I meant to choose C not B.
upvoted 2 times
wyindualizer
2 years, 1 month ago
https://learn.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook?tabs=LAC%2Cincidents when you create automation rule you can provite playbook (logic app) in action tab so firt you must create logic app and then automation rule
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago