HOTSPOT
-
You have an Azure subscription named Sub1 that contains a Microsoft Sentinel workspace named WS1.
You need to create a hunting query in WS1 that meets the following requirements:
• Returns the number of changes performed daily by each Microsoft Entra security principal during a seven-day period
• Identifies all the successful changes to the resources in Sub1
• Substitutes any missing data points with 0
How should you complete the KQL query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
rkrau
6 days, 4 hours ago