exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 9 discussion

Actual exam question from Microsoft's SC-200
Question #: 9
Topic #: 3
[All SC-200 Questions]

You have an Azure Sentinel workspace.
You need to test a playbook manually in the Azure portal.
From where can you run the test in Azure Sentinel?

  • A. Playbooks
  • B. Analytics
  • C. Threat intelligence
  • D. Incidents
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
HSBNZ
Highly Voted 3 years, 8 months ago
Manual triggering is available from the Azure Sentinel portal in the following blades: In Incidents view, choose a specific incident, open its Alerts tab, and choose an alert. In Investigation, choose a specific alert. Click on View playbooks for the chosen alert. You will get a list of all playbooks that start with an When an Azure Sentinel Alert is triggered and that you have access to. Click on Run on the line of a specific playbook to trigger it. Select the Runs tab to view a list of all the times any playbook has been run on this alert. It might take a few seconds for any just-completed run to appear in this list. Clicking on a specific run will open the full run log in Logic Apps.
upvoted 28 times
...
palito1980
Highly Voted 2 years, 2 months ago
Selected Answer: D
Clearly says to go to Incidents first. https://learn.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook?tabs=LAC%2Cincidents#run-a-playbook-manually-on-an-alert
upvoted 8 times
EM1234
1 year, 9 months ago
I did not mean to upvote this. Where in the question does it say there has been an alert? Did you just add that in?
upvoted 1 times
...
EM1234
1 year, 9 months ago
also, where does it say first?
upvoted 1 times
...
EM1234
1 year, 9 months ago
I do not like this question and D is a good choice but when I read the specific doc about testing playbooks (which I had not seen anyone link yet): https://learn.microsoft.com/en-us/azure/sentinel/automate-responses-with-playbooks#run-a-playbook-manually I see you can test the playbook three ways: To run a playbook on a specific incident To run a playbook on an alert To run a playbook on an entity
upvoted 4 times
EM1234
1 year, 9 months ago
Sorry I did not mean to hit submit yet, I will continue. So I see three ways to test but then this sentence: In any of these panels, you'll see two tabs: Playbooks and Runs. So then, I think in this poorly worded question you actually do click on "playbooks" to test. If I see this on the exam I am not sure which one I would choose, it could be a lot more clear than it is IMO.
upvoted 1 times
...
...
...
talosDevbot
Most Recent 7 months ago
Selected Answer: D
Sentinel > Incidents > click on an incident > Actions > Run Playbook
upvoted 1 times
...
Ramye
1 year, 2 months ago
Selected Answer: D
Confirmed from SC-200 Microsoft Practice Assessment https://learn.microsoft.com/en-us/credentials/certifications/exams/sc-200/practice/assessment?assessment-type=practice&assessmentId=59
upvoted 7 times
...
xoe123
1 year, 3 months ago
You can test a playbook manually in Azure Sentinel from both A. Playbooks and B. Incidents. A. Playbooks: You can run a playbook directly from the Playbooks blade in Azure Sentinel. This allows you to test the playbook independently of any incident or alert. B. Incidents: You can also run a playbook from an incident in Azure Sentinel. This allows you to test the playbook in the context of a specific incident.
upvoted 1 times
...
estyj
1 year, 3 months ago
D: Incidents https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/run-microsoft-sentinel-playbooks-from-workbooks-on-demand/ba-p/3193074
upvoted 1 times
...
chepeerick
1 year, 6 months ago
Option A
upvoted 1 times
...
danb67
1 year, 6 months ago
Selected Answer: D
D for me. Click on an incident then click on action and then run playbook
upvoted 1 times
...
mali1969
1 year, 8 months ago
Selected Answer: A
The answer is A. Playbooks. Playbooks are logic apps that allow you to automate and orchestrate your threat response in Azure Sentinel. You can create playbooks from templates or from scratch, and assign them to alerts or incidents to run automatically when triggered by an automation rule. You can also run playbooks manually on-demand, on a particular entity or alert, to test their functionality or perform a specific action.
upvoted 3 times
Ramye
1 year, 2 months ago
But the questions asked ---> From where can you run the test in Azure Sentinel? Your last sentence says - the answer is Incident.
upvoted 1 times
...
Anil0512
1 year, 7 months ago
bang on answer, cheers
upvoted 1 times
...
...
donathon
1 year, 8 months ago
Selected Answer: A
In the Playbooks tab, you'll see a list of all the playbooks that you have access to and that use the appropriate trigger - whether Microsoft Sentinel Incident, Microsoft Sentinel Alert, or Microsoft Sentinel Entity. Each playbook in the list has a Run button which you select to run the playbook immediately.
upvoted 3 times
sergioandreslq
7 months ago
Agree: In Microsoft Sentinel, you can manually test a playbook from the "Playbooks" blade. Here's how to do it: 1. Navigate to Microsoft Sentinel in the Azure portal. 2. Select the appropriate workspace. 3. In the left-hand menu, click on "Configuration" and then select "Playbooks." 4. Find the playbook you want to test and click on it to open its details. 5. At the top, you'll see an option to "Run playbook." Click this to start a manual test.
upvoted 1 times
...
...
itsadel
1 year, 9 months ago
Selected Answer: D
correct
upvoted 1 times
...
mimguy
1 year, 9 months ago
On the exam July 7 2023
upvoted 1 times
...
evilprime
2 years, 1 month ago
i think keyword is here is "test" why test a playbook on a actual incident.. go to playbooks and from there you can test it.
upvoted 1 times
7c0a
1 year, 10 months ago
Cause you need parameters(an array with entities), which are provided by the Sentinel trigger. Please stop using chatGPT for this matter, it is very unreliable approach, ChatGPT is good for other things, like generating basic code for most common/popular scenarios and languages, doing conversions, parsing, etc...
upvoted 4 times
...
...
[Removed]
2 years, 2 months ago
Selected Answer: A
A. Playbooks. To test a playbook manually in Azure Sentinel, you can use the "Test" feature in the Playbooks section of the Azure Sentinel workspace. To do this, navigate to the Azure Sentinel workspace in the Azure portal, click on "Playbooks" in the left-hand menu, and then select the playbook that you want to test. From there, click the "Test" button at the top of the page
upvoted 4 times
billo79152718
1 year, 10 months ago
You give chatgpt answers everytime. So many people here have commented on your alomst every time incorrect answers.
upvoted 6 times
...
...
teouba
2 years, 2 months ago
Selected Answer: A
You can run the test in Azure Sentinel from the "Playbooks" blade.
upvoted 4 times
...
kushagrasharma172
2 years, 4 months ago
Given answer is correct. Option D
upvoted 1 times
...
subhuman
3 years, 1 month ago
Selected Answer: D
Answer is Correct
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago