Management wants every High Microsoft Defender for Cloud incident in Microsoft Sentinel assigned to the SOC queue automatically. What should the Azure security engineer configure?
Select an answer to reveal the explanation.
Short Explanation
Don’t make analysts play hot potato with every High Defender alert. Drop an automation rule filtered by severity, product, or tactics that auto-assigns the SOC queue—and call Domain 4 done.
Full Explanation
Microsoft Sentinel automation rules can filter on severity, product, or tactics and assign an owner when incidents are created, including those sourced from Microsoft Defender for Cloud. Hunting notebooks and Security Copilot are not required for this ownership automation, and disabling analytics on High severity works against detection goals. This closes Domain 4 at Azure security-engineer depth without an SC-200 SOAR specialty dump.