Quiz 2 Question 14 of 20

A Microsoft Sentinel playbook must automatically isolate an Azure VM when Microsoft Defender for Endpoint detects that the VM has been used to exfiltrate data from an Azure OpenAI deployment. The playbook should trigger automatically when an incident is created. Which Sentinel feature enables automatic playbook execution?

Select an answer to reveal the explanation.

Motivation