Quiz 10 Question 4 of 20

A security team is building a Microsoft Sentinel analytics rule to detect when an AI application service principal authenticates from an unusual geographic location. The rule should correlate Entra ID sign-in logs with a watchlist of expected service principal locations. Which KQL approach is correct?

Select an answer to reveal the explanation.

Motivation