Quiz 15 Question 3 of 20

A security engineer needs to configure Microsoft Sentinel to automatically close a Defender for AI incident as a false positive when the source is a known internal penetration testing team's IP addresses. The pen test team's IPs are stored in a Sentinel watchlist. Which Microsoft Sentinel feature handles incident disposition automation?

Select an answer to reveal the explanation.

Motivation