Quiz 2 Question 15 of 20

A threat hunter is investigating potential data exfiltration from Azure OpenAI Service. Azure OpenAI diagnostic logs are ingested into Microsoft Sentinel. The hunter wants to find all instances where the token count in a single completion response exceeded 10,000 tokens in the last 24 hours. Which KQL query correctly retrieves this data?

Select an answer to reveal the explanation.

Motivation