SC-200 Practice Question 3806
Exam: SC-200
Domain: Respond to security incidents
Difficulty: easy
In Microsoft Sentinel, an incident involves a brute force attack targeting a virtual machine. You decide to block the attacking IP address using a firewall playbook. How is the playbook executed manually from the incident page?
Answer Options
A
Select "Actions" > "Run playbook", choose the playbook, and click Run
B
Type the playbook code into Windows Command Prompt
C
Restart the Log Analytics workspace
D
Email the playbook to the external firewall vendor
Correct Answer
A: Select "Actions" > "Run playbook", choose the playbook, and click Run
Explanation
On the incident details page, select "Actions" > "Run playbook", choose the remediation playbook, and click Run.