Question 1 of 30
In a security operations environment, you are tasked with automating incident response workflows using Azure Logic Apps. You need to integrate a Logic App with Azure Sentinel to trigger alerts based on specific conditions. Which of the following approaches would best facilitate this integration while ensuring that the Logic App can handle multiple types of alerts and maintain a clear audit trail of actions taken?
Create a Logic App that uses the Azure Sentinel connector to listen for alerts and then implement a series of actions based on the alert type, logging each action to an Azure Storage account for audit purposes.
Use a Logic App to poll Azure Sentinel for alerts at regular intervals and execute a single action for all alerts received, without logging actions taken.
Develop a custom API that sends alerts from Azure Sentinel to the Logic App, but do not include any logging mechanism for actions taken.
Configure Azure Sentinel to send alerts directly to an Azure Function, which then triggers the Logic App without any logging of actions taken.

Preparing for Microsoft SC-200 Microsoft Security Operations Analyst? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free