The lock-lab team already runs Microsoft Sentinel playbooks and also needs ticket creation when High alerts appear in Microsoft Defender for Cloud. Which statement correctly separates the two automation controls?
Select an answer to reveal the explanation.
Short Explanation
Two toolboxes, two labels. Defender for Cloud workflow automation kicks off from Defender alerts; Sentinel automation rules and playbooks live over in Sentinel. Either can call a Logic App—just don’t mash the controls together.
Full Explanation
Microsoft Defender for Cloud workflow automation is configured inside Defender for Cloud against alert or recommendation conditions. Microsoft Sentinel automation rules and playbooks are a separate Domain 4 control, even though both paths can invoke Azure Logic Apps. Candidates must not merge the products or substitute Security Copilot or Azure Policy as the official automation host for this skill.