High-severity Microsoft Sentinel incidents for lock-lab must tag the resource owner and run an isolate-virtual-machine Logic App. What should the Azure security engineer create?
Select an answer to reveal the explanation.
Short Explanation
Automation rule is the conductor; the playbook is the Logic App band. When a High incident lands, the rule fires and kicks the isolate-VM playbook—that’s the Sentinel automation pairing.
Full Explanation
In Microsoft Sentinel, an automation rule (for example, when an incident is created) orchestrates response actions and can run a playbook. Playbooks are Azure Logic Apps. This control is distinct from Microsoft Defender for Cloud workflow automation. Hunting notebooks and Azure Policy deny effects do not replace Sentinel automation rules that invoke playbooks.