Quiz 12 Question 15 of 20

A security engineer is analyzing Microsoft Sentinel incidents related to AI workloads. The engineer notices that many incidents are false positives because the Azure OpenAI diagnostic logs show legitimate batch processing jobs that spike token usage. Which Microsoft Sentinel feature allows the engineer to tune detection rules to reduce false positives from known legitimate behavior?

Select an answer to reveal the explanation.

Motivation