Quiz 10 Question 3 of 20

A security analyst is threat hunting for potential model inversion attacks against an Azure OpenAI deployment. The analyst wants to find API calls where the request body contains an unusually large number of tokens compared to the average. Which Microsoft Sentinel query approach should be used?

Select an answer to reveal the explanation.

Motivation