exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 4 discussion

Actual exam question from Microsoft's SC-200
Question #: 4
Topic #: 3
[All SC-200 Questions]

You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually.
You deploy Azure Sentinel.
You need to use the existing logic app as a playbook in Azure Sentinel.
What should you do first?

  • A. And a new scheduled query rule.
  • B. Add a data connector to Azure Sentinel.
  • C. Configure a custom Threat Intelligence connector in Azure Sentinel.
  • D. Modify the trigger in the logic app.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mmendozaf
Highly Voted 4 years, 1 month ago
Personally i think that correct option is D.
upvoted 43 times
prabhjot
3 years, 1 month ago
yes as Logic app is already available and it pre configure to trigger manual based ... now when you connect it as Playbook you need to change the Trigger from manual to ..Sentinel based so Option is D
upvoted 9 times
Atun23
2 years, 6 months ago
But how do you search for that activation event if the logs aren't coming to sentinel? The key is "Fisrt", you need to get the events onboarded and then import the app or chanf the trigger.
upvoted 6 times
7c0a
1 year, 10 months ago
You are overcomplicating this question, You deploy Azure Sentinel which includes some connectors and related analytical rules. It's pretty sure D.
upvoted 3 times
...
...
...
...
JhnCanthern12
Highly Voted 3 years, 10 months ago
Some people are saying this is correct as a logic app connector, actually this is referring to that as you have literally just deployed Sentinel, you need to add the AAD Connector to get that in first before you do anything. Need the data there first.
upvoted 24 times
madhatter
3 years, 10 months ago
agreed, you are working with an already deployed logic app and you just created a NEW sentinel deployment. You need the AAD Connector to send the data first. Provided answer "B" is correct.
upvoted 11 times
teehex
3 years, 9 months ago
No. There is nothing to do with AAD Connector. This is not about threat hunting against AAD. It is about how to integrate Azure Logic App to work with Azure Sentinel. You must modify existing Logic App and choose Azure Sentinel actions either the following ones: - When a response to an Azure Sentinel Alert is triggered - When Azure Sentinel incident creation rule was triggered
upvoted 12 times
PJR
3 years, 6 months ago
Before the alert can be triggered you need to ingest the source of the alert - ie connect Azure AD via a data connector. Given answer is correct
upvoted 7 times
...
...
...
...
Tuitor01
Most Recent 4 months, 4 weeks ago
Selected Answer: D
If you think about it, this question is not even a technical question, it's more like a 'common sense' question. Answer D, your trigger is a manual trigger, I doubt it would be useful when triggered from a Playbook.
upvoted 1 times
...
wheeldj
1 year ago
Selected Answer: D
Another poor question from MS I think. Define what 'deploy sentinel' means? if this implies you have literally just deployed a completely blank empty workspace then the answer is B. But if "you deploy Sentinel" means you build the workspace with the basic connectors and config to start ingesting data, then D is the answer. Working as a consultant if I told a customer I'd just 'Deployed Sentinel' but it had no data, no connectors, no rules I imagine they probably tell me to go back and finish the job! So I'm voting D
upvoted 3 times
...
Sneekygeek
1 year ago
Selected Answer: D
I was able to see my existing logic app under playbooks in Sentinel without creating a connector. Answer seems to be D
upvoted 1 times
...
Ramye
1 year, 2 months ago
Selected Answer: B
The Sentinel and AAD needs to integrate first before anything else, e.g. using the existing Logic App.
upvoted 1 times
...
estyj
1 year, 2 months ago
B. It said you just deployed Sentinel, so you have to add data connector to allow communication first before you can modify trigger for the alert.
upvoted 2 times
...
ing_magc
1 year, 3 months ago
the D is correct
upvoted 1 times
...
estyj
1 year, 3 months ago
Think it is B. You have just deployed sentinel. Have to able to communicate to Sentinel first so need to add data connector before you can modify trigger in logic app.
upvoted 1 times
...
chepeerick
1 year, 6 months ago
D for me
upvoted 1 times
...
danb67
1 year, 6 months ago
Selected Answer: B
B for me
upvoted 1 times
...
mali1969
1 year, 7 months ago
Selected Answer: D
D. Modify the trigger in the logic app. To use an existing logic app as a playbook in Azure Sentinel, you need to change the trigger from manual to When a response to an Azure Sentinel alert is triggered or When a response to an Azure Sentinel incident is triggered. This will allow the logic app to run automatically when an alert or incident occurs in Azure Sentinel.
upvoted 1 times
...
donathon
1 year, 8 months ago
Selected Answer: D
https://learn.microsoft.com/en-us/azure/sentinel/playbook-triggers-actions The answers are split between B and D. I will go for D because I think the AAD is already connected to the logic app. Whether AAD is connected to seninel or not does not really matters since the question is asking to add the logic app as a playbook. Which means D make more sense.
upvoted 2 times
...
promto
1 year, 10 months ago
Selected Answer: D
trigger
upvoted 1 times
...
haskelatchi
2 years ago
Selected Answer: B
Everyone the answer is B, confirmed and tested. Let me explain: Adding a data connector to Azure Sentinel is the first step to use the existing logic app as a playbook in Azure Sentinel. The data connector allows Azure Sentinel to trigger the Logic App as part of a playbook. Once the data connector is added, you can proceed to modify the trigger in the Logic App to ensure that it can be invoked by Azure Sentinel. It's important to note that modifying the trigger in the Logic App (option D) is also a crucial step in the process. However, based on the provided information, adding a data connector (option B) should be the first step.
upvoted 4 times
...
evilprime
2 years, 1 month ago
asked gpt the exact question with the exact answers to choose from, it has chosen B
upvoted 1 times
...
wsrudmen
2 years, 2 months ago
Selected Answer: B
It's B It's an exising logic App. If you want to modify the trigger, you will not find any trigger related to Sentinel (tested in lab). You have to add the connector before seeing the Sentinel Trigger. NB: For Playbook created directly in Sentinel, everything is done by default.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago