Quiz 15 Question 11 of 20

A security engineer needs to configure Microsoft Sentinel to detect when an Azure Machine Learning model training job accesses data outside its approved dataset scope. The engineer wants to detect when the training job service principal reads data from a storage account container not in the approved list. Which data source in Sentinel captures this activity?

Select an answer to reveal the explanation.

Motivation