Quiz 10 Question 2 of 20

A Microsoft Sentinel workspace receives alerts from Microsoft Defender for AI about anomalous usage of an Azure OpenAI endpoint. A security engineer wants to automate the response by adding the source IP to a watchlist for 24 hours. Which Microsoft Sentinel feature should be used to automate this response?

Select an answer to reveal the explanation.

Motivation