Quiz 5 Question 18 of 20

A Microsoft Sentinel analytics rule is enabled but never fires for lock-lab activity that should match. What should the Azure security engineer check next?

Select an answer to reveal the explanation.

Motivation