Quiz 6 Question 5 of 20

A security team notices that Microsoft Defender for Cloud has raised an alert for 'Anomalous access to Azure OpenAI' for a service principal that normally calls the API with consistent token counts between 500-1,000 per hour but suddenly made 50,000 calls in one hour. The team needs to determine whether this is a legitimate batch job or an attack. Which initial investigation step uses Microsoft Security Copilot most effectively?

Select an answer to reveal the explanation.

Motivation