nerdexam
Microsoft

MS-102 · Question #505

Your company has 5,000 Windows 10 devices. All the devices are protected by using Windows Defender Advanced Threat Protection (ATP). You need to view which Windows Defender ATP alert events have a…

The correct answer is B. Automated investigations. In Windows Defender ATP, Automated investigations surfaces alerts that have been triaged and investigated automatically, grouped by severity and time range, making it the intended interface for reviewing high-severity alert events within a specific window like the last seven…

Submitted by yuriko_h· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

Your company has 5,000 Windows 10 devices. All the devices are protected by using Windows Defender Advanced Threat Protection (ATP). You need to view which Windows Defender ATP alert events have a high severity and occurred during the last seven days. What should you use in Windows Defender ATP?

Options

  • Athe threat intelligence API
  • BAutomated investigations
  • CThreat analytics
  • DAdvanced hunting

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    83% (20)
  • C
    8% (2)
  • D
    4% (1)

Explanation

In Windows Defender ATP, Automated investigations surfaces alerts that have been triaged and investigated automatically, grouped by severity and time range, making it the intended interface for reviewing high-severity alert events within a specific window like the last seven days. Advanced hunting (D) is a KQL-based raw query tool suited for proactive threat hunting across telemetry data - it is more powerful but not the designed workflow for reviewing curated alert summaries by severity and recency. Threat analytics (C) provides macro-level intelligence on threat actor campaigns and techniques, not individual alert filtering. The threat intelligence API (A) is a programmatic interface for integrating external SIEM or SOAR platforms, not an in-portal alert review tool.

Topics

#Windows Defender ATP#Alert Filtering#Automated Investigations

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice