Either the answer is playbooks (which is not a provided choice) or the question itself is wrong. Workbooks does not provide for automation. It is a visualization / reporting tool. If you still doubt, look up "automate responses to threats detected by Azure Sentinel." in Google and you will find "Playbooks" in the results and nowhere will you find "Workbooks". I really love the spirit and intent of the site and have respect fort the small team behind it. At the same time I have to question where these questions came from. There are far too many discrepancies, errors and omissions to justify the asking price (which I regrettably paid as I thought my membership was for all tests, not just the AZ-900!). Clean up the discrepancies, errors and omissions (and include more than just one test) and it will be worth the asking price.
What you're saying is just wrong. The following link shows very clear that the given answer is the correct one: https://learn.microsoft.com/en-us/training/modules/protect-against-security-threats-azure/3-detect-respond-threats-sentinel?ns-enrollment-type=learningpath&ns-enrollment-id=learn.az-900-%20describe-general-security-network-security-features
I this is value for money. Time and time again pple are passing the exam using this site. you cant have everything handed to you on a plate. There is the option to pay $20 for 20 questions form MS if desired.
This answer is correct, see statement from Microsoft site:
Once you have connected your data sources to Microsoft Sentinel, you can visualize and monitor the data using the Microsoft Sentinel adoption of Azure Monitor Workbooks, which provides versatility in creating custom dashboards. While the Workbooks are displayed differently in Microsoft Sentinel, it may be useful for you to see how to create interactive reports with Azure Monitor Workbooks. Microsoft Sentinel allows you to create custom workbooks across your data, and also comes with built-in workbook templates to allow you to quickly gain insights across your data as soon as you connect a data source.
https://docs.microsoft.com/en-us/azure/sentinel/monitor-your-data
To automate responses to threats detected by Azure Sentinel, you should use option D: adaptive application controls in Azure Security Center.
Azure Security Center provides adaptive application controls, which allow you to automatically respond to threats detected by Azure Sentinel. These controls enable you to define and enforce policies that govern the types of applications allowed to run on your virtual machines (VMs) and servers. By configuring adaptive application controls, you can automatically block or allow applications based on predefined rules and policies, helping to mitigate security risks and protect your environment from potential threats.
C is the answer.
https://learn.microsoft.com/en-us/azure/sentinel/monitor-your-data
Once you have connected your data sources to Microsoft Sentinel, you can visualize and monitor the data using the Microsoft Sentinel adoption of Azure Monitor Workbooks, which provides versatility in creating custom dashboards. While the Workbooks are displayed differently in Microsoft Sentinel, it may be useful for you to see how to create interactive reports with Azure Monitor Workbooks. Microsoft Sentinel allows you to create custom workbooks across your data, and also comes with built-in workbook templates to allow you to quickly gain insights across your data as soon as you connect a data source.
Yup, it says it right here - Azure Monitor Workbooks
"The company will also use Azure Monitor Workbooks to automate responses to threats."
https://docs.microsoft.com/en-us/learn/modules/protect-against-security-threats-azure/3-detect-respond-threats-sentinel?ns-enrollment-type=learningpath&ns-enrollment-id=learn.az-900-
describe-general-security-network-security-features
C for me
"The company will also use Azure Monitor Workbooks to automate responses to threats."
https://docs.microsoft.com/en-us/learn/modules/protect-against-security-threats-azure/3-detect-respond-threats-sentinel?ns-enrollment-type=learningpath&ns-enrollment-id=learn.az-900-describe-general-security-network-security-features
Odd one out but I would disagree with answer. Workbooks are just dashboard and takes no action themselves.
Sentinel uses playbook against known situations but playbook uses two things among others Adaptive network hardening (to reduce attack surface) and Adaptive Application Control (to have a known safe application list & block application on suspicious behavior). Since the Application control needs advance work, I would say surface reduction would be first choice in case of any attack. Hence A
I think it should be Playbooks,
https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook
https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook
I agree - it should be Azure Logic Apps.
"Automate your common tasks and simplify security orchestration with playbooks that integrate with Azure services and your existing tools.
Built on the foundation of Azure Logic Apps..."
https://docs.microsoft.com/en-us/azure/sentinel/overview
Yes , I too think it should be Azure logic Apps :-
https://www.xenonstack.com/blog/azure-sentinel-and-its-components#:~:text=Azure%20Sentinel%20is%20a%20SIEM,proactive%20hunting%2C%20and%20threat%20response.
Playbooks: A Playbook is a collection of procedures to execute in response to an alert trigger by Azure Sentinel. They leverage Azure Logic Apps. So, the user can use flexibility, capability, customizability, and built-in templates of Logic Apps. To automate and orchestrate tasks/workflows that can be ready to configure to run manually or execute automatically when specific alerts are triggered.
But it isn't available in the options lol
This section is not available anymore. Please use the main Exam Page.AZ-900 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
kwldgseeker
Highly Voted 3 years agoNoursBear
9 months, 1 week ago[Removed]
2 years, 2 months agoNi_yot
2 years, 2 months agoTamHas
Highly Voted 3 years, 3 months agoNoursBear
6 months, 3 weeks agoAndrikon
Most Recent 1 week, 1 day agoPN60
6 months, 1 week agoJUMP56
10 months, 2 weeks agoPayu1994
1 year agoSAFM
1 year, 6 months agozellck
2 years, 3 months agoAnitaArab
2 years, 5 months agoNoursBear
6 months, 3 weeks agoHHHo
3 years agoTin_Nguyen
3 years agoContactfornitish
3 years, 1 month agoforestwood
3 years, 2 months agoblobstorage
3 years, 3 months agonsp24
3 years, 3 months agoTheKraemer
3 years, 3 months agojohnny1001
3 years, 1 month agoBorbala
3 years, 3 months agonimblealliance
3 years ago