Quiz 15 Question 13 of 20

An organization is building a Microsoft Sentinel analytics rule to detect potential training data exfiltration from an Azure Machine Learning workspace. The analyst wants to alert when a data scientist downloads more than 1 GB of data from the training data storage account in a single day. Which KQL approach correctly implements this volume-based detection?

Select an answer to reveal the explanation.

Motivation