exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 1 question 7 discussion

Actual exam question from Microsoft's SC-100
Question #: 7
Topic #: 1
[All SC-100 Questions]

Your company is moving all on-premises workloads to Azure and Microsoft 365.
You need to design a security orchestration, automation, and response (SOAR) strategy in Microsoft Sentinel that meets the following requirements:
✑ Minimizes manual intervention by security operation analysts
✑ Supports triaging alerts within Microsoft Teams channels
What should you include in the strategy?

  • A. KQL
  • B. playbooks
  • C. data connectors
  • D. workbooks
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
prabhjot
Highly Voted 2 years, 9 months ago
sentinel soar= playbook (logic app), so correct ans
upvoted 14 times
...
PlumpyTumbler
Highly Voted 2 years, 9 months ago
Selected Answer: B
https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook?tabs=LAC
upvoted 8 times
...
Gagi79
Most Recent 1 month, 1 week ago
Selected Answer: B
To design a security orchestration, automation, and response (SOAR) strategy in Microsoft Sentinel that minimizes manual intervention by security operation analysts and supports triaging alerts within Microsoft Teams channels, you should include: B. playbooks Playbooks in Microsoft Sentinel allow you to automate responses to alerts and incidents, significantly reducing the need for manual intervention by security analysts. Additionally, playbooks can be configured to send alerts and notifications to Microsoft Teams channels, facilitating effective communication and triaging among team members. While KQL (A) is essential for querying data, data connectors (C) are used for integrating various data sources, and workbooks (D) provide visualizations and reporting, none of these options specifically address automation and alert triaging in the context of your requirements as effectively as playbooks do.
upvoted 1 times
...
AJ2021
8 months, 2 weeks ago
Selected Answer: B
https://learn.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook?tabs=LAC%2Cincidents Playbooks are collections of procedures that can be run from Microsoft Sentinel in response to an alert or incident. A playbook can help automate and orchestrate your response, and can be set to run automatically when specific alerts or incidents are generated, by being attached to an analytics rule or an automation rule, respectively. It can also be run manually on-demand. Playbooks in Microsoft Sentinel are based on workflows built in Azure Logic Apps, which means that you get all the power, customizability, and built-in templates of Logic Apps. Each playbook is created for the specific subscription to which it belongs, but the Playbooks display shows you all the playbooks available across any selected subscriptions.
upvoted 2 times
...
zellck
8 months, 2 weeks ago
Selected Answer: B
B is the answer. https://learn.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook?tabs=LAC%2Cincidents#what-are-automation-rules-and-playbooks Playbooks are collections of procedures that can be run from Microsoft Sentinel in response to an alert or incident. A playbook can help automate and orchestrate your response, and can be set to run automatically when specific alerts or incidents are generated, by being attached to an analytics rule or an automation rule, respectively. It can also be run manually on-demand.
upvoted 2 times
...
JG56
1 year, 6 months ago
Selected answer: B,
upvoted 3 times
...
Gurulee
2 years, 1 month ago
Selected Answer: B
"Minimizes manual intervention", this requires Playbooks
upvoted 2 times
...
fchahin
2 years, 2 months ago
Selected Answer: B
Answer is B
upvoted 3 times
...
OCHT
2 years, 2 months ago
Selected Answer: C
Data connecter
upvoted 1 times
...
adamsca
2 years, 3 months ago
Selected Answer: C
Correct
upvoted 1 times
...
Learing
2 years, 7 months ago
Selected Answer: B
correct
upvoted 2 times
...
TJ001
2 years, 9 months ago
correct answer
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...