Which TWO built-in Microsoft Sentinel hunting queries are useful for detecting signs of compromised credentials?
Identifies logins from unexpected geographies.
Why this answer
Correct options: B and C. Anomalous logon location (B) can indicate credential misuse. Brute force attempt (C) detects password guessing.
Option A (Baseline) is not a specific query. Option D (New user) may be legitimate. Option E (Deleted) is not specific to compromise.