Your organization uses Microsoft Sentinel. You need to ensure that incident response times are monitored and reported. Which TWO capabilities should you use?
Automation rules in Sentinel are the correct choice because they let you define conditions and run actions when an incident is created or updated, including updating fields and setting tags. By configuring a rule that stamps the incident's 'Created' time and another that records when the incident transitions to 'In Progress' or is assigned, you can capture the exact response start time. This information is stored in the incident's properties and can later be queried to compute time-to-respond, directly enabling monitoring of response times.
Why this answer
Automation rules (C) are correct because they allow you to define conditions and actions that automatically trigger when an incident is created or updated, enabling consistent assignment, severity changes, and tagging. Workbooks (E) are correct because they provide customizable visualizations and reports that can track key metrics like incident response times, mean time to acknowledge (MTTA), and mean time to remediate (MTTR) using KQL queries against Sentinel's security data.
Exam trap
The trap here is that candidates often confuse playbooks (automated response actions) with automation rules (incident orchestration) and overlook workbooks in favor of UEBA or watchlists, which are unrelated to monitoring response times.