nerdexam
Microsoft

MS-102 · Question #542

Your company has 5,000 Windows 10 devices. All the devices are protected by using Windows Defender Advanced Threat Protection (ATP). You need to create a filtered view that displays which Windows…

The correct answer is D. Advanced hunting. Advanced hunting allows you to create a query that proccesses 30 days of raw data and outputs the info asked for. Automated investigations handles itself by starting a scan once alerted and remidiates the issue

Submitted by emma.c· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

Your company has 5,000 Windows 10 devices. All the devices are protected by using Windows Defender Advanced Threat Protection (ATP). You need to create a filtered view that displays which Windows Defender ATP alert events have a high severity and occurred during the last seven days. What should you use in Windows Defender ATP?

Options

  • Athe threat intelligence API
  • BAutomated investigations
  • CThreat analytics
  • DAdvanced hunting

How the community answered

(45 responses)
  • A
    9% (4)
  • B
    2% (1)
  • C
    18% (8)
  • D
    71% (32)

Explanation

Advanced hunting allows you to create a query that proccesses 30 days of raw data and outputs the info asked for. Automated investigations handles itself by starting a scan once alerted and remidiates the issue

Topics

#Windows Defender ATP#Advanced hunting#Alert filtering#Severity-based queries

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice