correct answer
「Playbooks are collections of procedures that can be run from Azure Sentinel in response to an alert or incident. A playbook can help automate and orchestrate your response, and can be set to run automatically when specific alerts or incidents are generated, by being attached to an analytics rule or an automation rule, respectively. It can also be run manually on-demand.」
https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook
A resposta correta para a pergunta é: ✅ "automatically respond to threats."
🔧 Explicação:
Playbooks no Azure Sentinel são fluxos de trabalho automatizados que usam Azure Logic Apps para responder automaticamente a ameaças. Quando um alerta é gerado, o Sentinel pode acionar um playbook para tomar ações como:
Isolar máquinas infectadas 🖥️🔒
Bloquear endereços IP suspeitos 🚫🌐
Notificar a equipe de segurança 📩🔔
Integrar com ferramentas externas como Teams, Email ou outras plataformas SIEM
"automatically respond to threats" is the answer.
https://learn.microsoft.com/en-us/azure/sentinel/automate-responses-with-playbooks#what-is-a-playbook
A playbook is a collection of these remediation actions that can be run from Microsoft Sentinel as a routine. A playbook can help automate and orchestrate your threat response; it can be run manually on-demand on entities (in preview - see below) and alerts, or set to run automatically in response to specific alerts or incidents, when triggered by an automation rule.
For example, if an account and machine are compromised, a playbook can isolate the machine from the network and block the account by the time the SOC team is notified of the incident.
This section is not available anymore. Please use the main Exam Page.AZ-900 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
mintyo
Highly Voted 3 years, 10 months agoRcosmos
Most Recent 5 days, 8 hours agoPN60
9 months, 1 week agoPN60
9 months, 1 week agozellck
2 years, 6 months agozellck
2 years, 6 months agokamal_004
2 years, 9 months agocsboy
3 years, 4 months agoMS_Learner
3 years, 5 months agoLiamAltaii
3 years, 7 months agoeasygo68
3 years, 8 months agoVincenzo_Cassano
3 years, 9 months agoAlaCh
3 years, 9 months ago