MS-102 · Question #119
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint. All the devices in your organization are onboarded to Microsoft Defender for Endpoint. You need to ensure that an…
The correct answer is C. From Advanced hunting, create a query and a detection rule. Advanced hunting allows you to create custom queries to search for specific events in your environment. You can then use these queries to create detection rules that will generate alerts when certain events occur.
Question
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint. All the devices in your organization are onboarded to Microsoft Defender for Endpoint. You need to ensure that an alert is generated if malicious activity was detected on a device during the last 24 hours. What should you do?
Options
- AFrom the Microsoft Purview compliance portal, create a data loss prevention (DLP) policy.
- BFrom Alerts queue, create a suppression rule and assign an alert.
- CFrom Advanced hunting, create a query and a detection rule.
- DFrom the Microsoft Purview compliance portal, create an audit log search.
How the community answered
(38 responses)- A3% (1)
- B8% (3)
- C74% (28)
- D16% (6)
Explanation
Advanced hunting allows you to create custom queries to search for specific events in your environment. You can then use these queries to create detection rules that will generate alerts when certain events occur.
Topics
Community Discussion
No community discussion yet for this question.