Quiz 12 Question 3 of 20

A Microsoft Sentinel analytics rule needs to detect when an Azure OpenAI model is being used to generate large volumes of similar requests in a short period, potentially indicating automated abuse. A security engineer writes a KQL query to detect this. Which KQL operator is most appropriate for identifying time-windowed frequency anomalies?

Select an answer to reveal the explanation.

Motivation