You are a security operations analyst at a company that uses Microsoft Sentinel. You need to create an automation rule that automatically closes incidents with a severity of Informational and a status of New after 24 hours, but only if they do not contain any entities. Which three conditions must you configure in the automation rule?
Trap 1: Severity equals Low, Status equals New, and Entities count equals 0.
It uses Severity equals Low instead of Informational. Severity levels in Microsoft Sentinel include High, Medium, Low, and Informational. The scenario specifically requires Informational severity, so using Low would target the wrong incidents and fail to meet the requirement.
Trap 2: Severity equals Informational, Status equals New, and Entities…
It uses Entities count greater than 0. The scenario requires incidents with no entities. Using greater than 0 would select incidents that do contain entities, which is the opposite of what is needed, and would not automatically close the intended incidents.
Trap 3: Severity equals Informational, Status equals Active, and Entities…
It uses Status equals Active instead of New. The scenario specifies incidents with a status of New. In Microsoft Sentinel, incident statuses include New, Active, and Closed. Using Active would not match the intended incidents, potentially leaving New incidents unclosed or affecting the wrong set.
- A
Severity equals Low, Status equals New, and Entities count equals 0.
Why it fails: It uses Severity equals Low instead of Informational. Severity levels in Microsoft Sentinel include High, Medium, Low, and Informational. The scenario specifically requires Informational severity, so using Low would target the wrong incidents and fail to meet the requirement.
- B
Severity equals Informational, Status equals New, and Entities count equals 0.
This option correctly identifies the three conditions required: severity equal to Informational, status equal to New, and no entities present. These conditions ensure that only low-priority incidents without entities are automatically closed after the specified time, aligning with the scenario's requirement to reduce noise from such incidents.
- C
Severity equals Informational, Status equals New, and Entities count greater than 0.
Why it fails: It uses Entities count greater than 0. The scenario requires incidents with no entities. Using greater than 0 would select incidents that do contain entities, which is the opposite of what is needed, and would not automatically close the intended incidents.
- D
Severity equals Informational, Status equals Active, and Entities count equals 0.
Why it fails: It uses Status equals Active instead of New. The scenario specifies incidents with a status of New. In Microsoft Sentinel, incident statuses include New, Active, and Closed. Using Active would not match the intended incidents, potentially leaving New incidents unclosed or affecting the wrong set.