A SOC analyst needs to automatically close low-fidelity alerts in Microsoft Sentinel after 7 days if no activity occurs. Which automation feature should they configure?
-
A
Playbook triggered on alert creation
-
B
Automation rule with 'Close incident' action after time condition
-
C
Workbook with scheduled refresh
-
D
Analytic rule with suppression enabled