SC-200 Practice Question 3806

Exam: SC-200
Domain: Respond to security incidents
Difficulty: easy
In Microsoft Sentinel, an incident involves a brute force attack targeting a virtual machine. You decide to block the attacking IP address using a firewall playbook. How is the playbook executed manually from the incident page?

Answer Options

A
Select "Actions" > "Run playbook", choose the playbook, and click Run
B
Type the playbook code into Windows Command Prompt
C
Restart the Log Analytics workspace
D
Email the playbook to the external firewall vendor

Correct Answer

A: Select "Actions" > "Run playbook", choose the playbook, and click Run

Explanation

On the incident details page, select "Actions" > "Run playbook", choose the remediation playbook, and click Run.