While working an elections investigation in Enterprise Security, the analyst needs to launch playbook actions as part of the case workflow. Which trigger path does this describe?
Select an answer to reveal the explanation.
Short Explanation
A response plan is the case folder with the next buttons already printed. While the elections investigation is open, the analyst launches those playbook actions from the plan. That is a third trigger path besides scheduled AR and a one-off queue click.
Full Explanation
Enterprise Security investigations can include a response plan with playbook actions the analyst launches while working the case. That is a named ES-to-SOAR trigger path alongside scheduled AR and ad-hoc queue actions. CIM extractions, tstats-only searches, and indexer restarts do not invoke playbooks.