Quiz 3 Question 8 of 20

A Microsoft Sentinel analytics rule fires an alert for a suspected Azure OpenAI abuse incident. The security team wants to ensure that entity information (the source IP address and the Azure OpenAI resource name) is automatically mapped and enriched in the incident so analysts can pivot to entity pages immediately. Which Sentinel analytics rule configuration enables this?

Select an answer to reveal the explanation.

Motivation