Quiz 5 Question 18 of 20

A Microsoft Sentinel analytics rule needs to be created to detect when an Azure OpenAI API key stored in Azure Key Vault is accessed by a service principal that is not in a pre-approved list. The analyst has a Sentinel watchlist named 'ApprovedAIServicePrincipals' with the approved ObjectIds. Which KQL approach correctly implements this detection?

Select an answer to reveal the explanation.

Motivation