certslothcertsloth
SC-500/Topic 11

Azure / Associate

Sentinel, Incident Automation and Security Copilot

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Collect the right evidence, correlate it, then authorise every response action.

Must remember

  • Sentinel uses supported workspaces, data connectors, analytics content and incident workflows. Assign appropriate Sentinel/workspace roles. Content Hub solutions supply supported connectors/rules/workbooks; installing content is not the same as configuring data collection.
  • Syslog/CEF, Windows Security events and WEF require the correct collection pipeline, agent/forwarder and data collection rules. Custom logs need appropriate tables/schema and ingestion configuration. Verify arrival, parsing, timestamps and retention before relying on detections.
  • Analytics rules correlate events into alerts/incidents under their configuration. Automation rules coordinate incident handling; playbooks use Logic Apps for response. Scope managed identities and target permissions, add approvals where needed and make actions idempotent.
  • Define retention for relevant data stores based on investigation and cost needs. A missing event may reflect connector permissions, DCR configuration, network, parser or retention failure. Query Purview Audit through supported Defender XDR capabilities for the relevant audit scenario.
  • Security Copilot workspaces, roles, plugins and supported agents control who can use which capabilities. Enable only needed plugins and review their data/action access. Microsoft and Security Store agents need the same ownership, evaluation and permission discipline as other automation.
  • Treat generated investigation summaries as assistance that requires evidence validation. Preserve source links, analyst decisions and response audit. A confidently worded recommendation is not authorisation to isolate a business-critical service without the defined response process.

Choose under exam pressure

Requirement Choice and reason
No Windows events appear in Sentinel Inspect collection rules, forwarding/agent, connector and workspace arrival.
Repeated incident needs a standard response Automation rule plus a scoped, tested playbook.
Copilot must use one external capability Enable the specific plugin with reviewed permissions.

Traps

  • Content installation does not prove telemetry is flowing.
  • A playbook can have broader permissions than its trigger author.
  • AI-generated incident analysis can contain unsupported conclusions.

Active recall

1. What distinguishes an automation rule from a playbook?

The rule controls incident automation logic; the playbook executes a workflow of actions.

2. Why check timestamps and parsing?

Bad normalisation can break correlation or make events appear outside the queried window.

3. What should a response workflow preserve?

Evidence, action identity, inputs/results, approvals and a recovery path.

4. Why scope Copilot plugins?

They extend accessible data/tools and therefore the potential exposure or action surface.

5. How should a generated incident conclusion be validated?

Against the underlying telemetry and established investigation/response procedure.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.