Quiz 14 Question 9 of 20

A security engineer is investigating a Microsoft Sentinel incident that correlates multiple low-severity alerts into a high-confidence incident via the Fusion detection engine. The incident involves an anomalous Azure OpenAI usage spike following a compromised service principal sign-in. The engineer wants to understand how Fusion determined these alerts are related. Where can the engineer review the Fusion correlation logic?

Select an answer to reveal the explanation.

Motivation