MS-102 · Question #376
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint. All the devices in your organization are onboarded to Microsoft Defender for Endpoint. You need to ensure that an…
The correct answer is D. From the Microsoft Defender portal, create an Advanced hunting query and a detection rule. To generate custom alerts for specific malicious activity within a defined timeframe in Microsoft Defender for Endpoint, you should create an Advanced hunting query and then configure a custom detection rule based on it.
Question
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint. All the devices in your organization are onboarded to Microsoft Defender for Endpoint. You need to ensure that an alert is generated if malicious activity was detected on a device during the last 24 hours. What should you do?
Options
- AFrom the Microsoft Purview compliance portal, create a data loss prevention (DLP) policy.
- BFrom the Microsoft Defender portal, create an alert suppression rule and assign an alert.
- CFrom Advanced hunting, create a query and a detection rule.
- DFrom the Microsoft Defender portal, create an Advanced hunting query and a detection rule.
How the community answered
(50 responses)- A10% (5)
- B2% (1)
- C4% (2)
- D84% (42)
Why each option
To generate custom alerts for specific malicious activity within a defined timeframe in Microsoft Defender for Endpoint, you should create an Advanced hunting query and then configure a custom detection rule based on it.
The Microsoft Purview compliance portal and DLP policies are used for data loss prevention and managing sensitive information, not for generating alerts based on malicious activity detected by Defender for Endpoint.
Creating an alert suppression rule is used to prevent alerts from being generated for specific activity, which is the opposite of the requirement to generate an alert.
While creating an Advanced hunting query and a detection rule is correct, specifying "From Advanced hunting" only is less precise than "From the Microsoft Defender portal, create an Advanced hunting query and a detection rule," as Advanced hunting is a feature within the Microsoft Defender portal, making D the more complete and accurate answer.
From the Microsoft Defender portal, creating an Advanced hunting query and a detection rule is the correct approach to generate custom alerts for specific malicious activities. Advanced hunting allows you to write Kusto Query Language (KQL) queries to look for specific patterns or activities (like malicious activity in the last 24 hours), and then a custom detection rule can be configured to trigger an alert and assign an action whenever that query returns results.
Concept tested: Defender for Endpoint custom detection rules and Advanced hunting
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/custom-detection-rules?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.