Correct Answer: D
You must first connect Azure Sentinel to Azure AD Identity Protection to receive alert data into Sentinel
Option A is incorrect. While you can use Logic Apps in playbooks to automate your incident response and remediate security threats detected by Azure Sentinel, you first have to connect Sentinel to Azure AD Identity Protection to receive data into the solution.
Option B is incorrect. Workbooks allows you to visualize and monitor data received from a connected source. Hence not the correct answer.
Option C is incorrect. Playbooks are indeed created to automate and orchestrate response to incidents and security threats based on workflows built in Azure Logic Apps. But in this scenario you first have to connect Azure Sentinel to the Identity Protection data source. Hence it is not the correct answer.
Reference:
To know more about connecting Sentinel to identity protection, please refer to the link below:
https://docs.microsoft.com/en-us/azure/sentinel/connect-azure-ad-identity-protection