nerdexam
Microsoft

MS-102 · Question #119

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint. All the devices in your organization are onboarded to Microsoft Defender for Endpoint. You need to ensure that an…

The correct answer is C. From Advanced hunting, create a query and a detection rule. Advanced hunting allows you to create custom queries to search for specific events in your environment. You can then use these queries to create detection rules that will generate alerts when certain events occur.

Submitted by takeshi77· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint. All the devices in your organization are onboarded to Microsoft Defender for Endpoint. You need to ensure that an alert is generated if malicious activity was detected on a device during the last 24 hours. What should you do?

Options

  • AFrom the Microsoft Purview compliance portal, create a data loss prevention (DLP) policy.
  • BFrom Alerts queue, create a suppression rule and assign an alert.
  • CFrom Advanced hunting, create a query and a detection rule.
  • DFrom the Microsoft Purview compliance portal, create an audit log search.

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    74% (28)
  • D
    16% (6)

Explanation

Advanced hunting allows you to create custom queries to search for specific events in your environment. You can then use these queries to create detection rules that will generate alerts when certain events occur.

Topics

#Microsoft Defender for Endpoint#Advanced hunting#Custom detection rules#Threat detection

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice