Using Sentinel automation rules and playbooks to minimize incident response effort

Configure automation for Microsoft Defender XDR and Microsoft Sentinel
Answer Correct answer: C, D — Sentinel automation rules and playbooks together automate triage and remediation, minimizing manual response effort.

You have an Azure subscription that uses Microsoft Sentinel. You need to minimize the administrative effort required to respond to the incidents and remediate the security threats detected by Microsoft Sentinel. Which two features should you use? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  1. Microsoft Sentinel workbooks
  2. Azure Automation runbooks
  3. Microsoft Sentinel automation rules Correct Answer
  4. Microsoft Sentinel playbooks Correct Answer
  5. Azure Functions apps

Community Votes

CD
100%

100% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Automation rules and playbooks are Sentinel's native response-automation pair: automation rules decide what happens when an incident is created, and playbooks execute the remediation logic, together reducing manual effort.

To minimize the administrative effort of responding to and remediating Sentinel incidents, use Microsoft Sentinel automation rules (which triage and auto-assign/close) together with playbooks (which run automated response actions), so the two features are the answer.

Choosing workbooks or Azure Automation runbooks/Functions — workbooks are for visualization, and Azure Automation runbooks/Functions are not the Sentinel-native pair the question targets for incident response.

Community Discussion (4 comments)

smanzana 👍 4
Correct
Hawklx 👍 4
same question as 37 topic 3
MadLads 👍 2 Selected: CD
By using Microsoft Sentinel automation rules and Microsoft Sentinel playbooks, you can effectively automate the detection, response, and remediation processes, reducing the manual effort required and ensuring quicker and more consistent handling of security incidents.
RedZtopics 👍 2
for me B and D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Sentinel automation rules and playbooks work together to automate incident response and remediation. Automation rules can automatically assign, tag, close, or trigger playbooks on incident creation, while playbooks (Logic Apps) run the actual response actions. This combination minimizes manual effort, which is exactly the requirement.

Why the Other Options Are Wrong

Sentinel workbooks (A) are for visualizing data, not responding. Azure Automation runbooks (B) and Azure Functions (E) are general Azure automation, not the Sentinel-native automation/playbook pair the question asks for.

Community Comment Notes

The community is unanimous (CD 100). MadLads explains that automation rules and playbooks automate detection, response, and remediation, reducing manual effort. Hawklx notes it is the same as an earlier question, and RedZtopics mistakenly suggests B and D, but the documented pair is automation rules + playbooks.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide