HOTSPOT -
You have an Azure subscription that contains a Microsoft Sentinel workspace.
You need to create a hunting query using Kusto Query Language (KQL) that meets the following requirements:
• Identifies an anomalous number of changes to the rules of a network security group (NSG) made by the same security principal.
• Automatically associates the security principal with a Microsoft Sentinel entity.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Anil0512
Highly Voted 1 year, 9 months agodanb67
1 year, 8 months agoAnil0512
1 year, 9 months agochepeerick
Highly Voted 1 year, 8 months agoOneplusOne
Most Recent 1 month, 1 week agosmanzana
11 months ago7d801bf
11 months, 4 weeks agofbernis
1 year, 4 months ago