Your question is Design Login Anomaly Detection Features. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
You are building an ML system for a security product that flags suspicious login activity and possible account takeover attempts. The system needs to score login events in near real time and help downstream enforcement decide whether to allow, challenge, or block access.
What features would you engineer to detect anomalous login behaviors or account takeover attempts?