You have a Microsoft 36S ES tenant that contains 100 Windows 10 devices.
You plan to use attack surface reduction (ASR) rules tor the Windows 10 devices.
You configure the ASR rules in audit mode and collect audit data in a Log Analytics workspace.
You need to find the ASR rules that match the activities on the devices.
How should you complete the Kusto query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Currently there are no comments in this discussion, be the first to comment!