High Microsoft Defender for Cloud alerts on lock-lab resources must open a ticket and email the on-call engineer. Which automation should the Azure security engineer configure?
Select an answer to reveal the explanation.
Short Explanation
Want tickets and on-call pings without babysitting the blade? Wire Defender for Cloud workflow automation to a Logic App that fires on those High alert conditions—that’s the in-product automation path.
Full Explanation
Microsoft Defender for Cloud workflow automation runs on alert or recommendation conditions and commonly invokes an Azure Logic App to open tickets, send email, or take other actions. Security Copilot agents are not the AZ-500 answer for this control. Azure Policy does not replace alert-driven workflow automation, and Sentinel hunting notebooks address a different product workflow.