AZ-500 exam dumps

AZ-500 practice question 255 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 255

Single answer

Your organization uses Microsoft Sentinel to aggregate security logs from various sources. You have created an Azure Logic App that automatically blocks suspicious IP addresses when triggered by high-severity incidents in Microsoft Sentinel. Which action must you take to ensure that Sentinel automatically invokes your Logic App whenever a new high-severity incident is generated?

  1. A

    Enable the 'Incident Auto-Enrich' feature in Microsoft Sentinel

  2. B

    Create an Automation Rule in Microsoft Sentinel that calls your Logic App for high-severity incidents

  3. C

    Add a user-assigned managed identity to the Logic App

  4. D

    Turn on Azure Monitor diagnostic logs for the Logic App to track all trigger details

Show answer and explanation

Correct answer: B

Explanation

To automate responses in Microsoft Sentinel, you must create Automation Rules that specify the conditions (such as incident severity) and the action (such as calling a Logic App). Refer to the official Microsoft Sentinel documentation (https://docs.microsoft.com/azure/sentinel/automate-incident-handling-with-automation-rules) for guidance on setting up automation rules and playbooks to respond to security threats in real time.

  • A. Incorrect.

    Option 1 is incorrect. While Microsoft Sentinel can enrich incidents with additional data, there is no feature called ‘Incident Auto-Enrich’ that automatically invokes a Logic App. Sentinel relies on automation rules and playbooks to trigger workflows.

  • B. Correct.

    Option 2 is correct. Microsoft Sentinel must have an Automation Rule configured to call your Logic App (often referred to as a playbook) whenever an incident meets specific conditions, such as a high-severity rating. This is the essential configuration step to ensure automatic triggering.

  • C. Incorrect.

    Option 3 is incorrect. While user-assigned managed identities can be used for authentication when your Logic App needs to access resources, simply adding a managed identity does not create or configure the trigger for high-severity incidents. An automation rule is still needed.

  • D. Incorrect.

    Option 4 is incorrect. Enabling diagnostic logs on your Logic App can help track execution and troubleshooting, but it does not enable the Logic App to be triggered by Microsoft Sentinel. You still need a Sentinel Automation Rule.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam