Which TWO actions can be performed using Microsoft Sentinel automation rules? (Select TWO.)
Within Microsoft Sentinel, an incident can be assigned to a specific SOC analyst either manually through the incident details pane or automatically via an automation rule action that sets the incident owner. Automation rules use conditions like severity or entity to route ownership to a chosen user or group, ensuring immediate accountability. This action is one of the incident-management capabilities that make Sentinel a central SOC workspace.
Why this answer
Automation rules in Microsoft Sentinel allow you to automate incident management tasks, such as assigning incidents to specific SOC analysts based on criteria like severity or type. This is a core capability of automation rules, which can set the owner of an incident to a specific user or group, enabling efficient triage and accountability.
Exam trap
The trap here is that candidates often confuse automation rules with playbooks or analytics rules, assuming automation rules can create or modify detection logic, when in fact they are strictly for incident response and management actions.