Quiz 5 Question 7 of 20

An organization's SOC team wants to proactively hunt for signs that an AI model API key has been leaked and is being used from external IP addresses. Azure OpenAI diagnostic logs are in Sentinel. Which KQL hunting query approach identifies calls from IPs not seen in the previous 30 days?

Select an answer to reveal the explanation.

Motivation