SC-200 · Question #244
You have a Microsoft 365 subscription that uses Microsoft Purview and Microsoft Teams. You have a team named Team1 that has a project named Project1. You need to identify any Project1 files that…
The correct answer is C. Project1(c:c)(date=2023-02-01..2023-02-10). To search for specific content within a date range in Microsoft Purview, the KQL query should specify the keyword, content property, and date range in the correct format.
Question
You have a Microsoft 365 subscription that uses Microsoft Purview and Microsoft Teams. You have a team named Team1 that has a project named Project1. You need to identify any Project1 files that were stored on the team site of Team1 between February 1, 2023, and February 10, 2023. Which KQL query should you run?
Options
- A(c:c)(Project1)(date=(2023-02-01)..date=(2023-02-10))
- BAuditLogs
- CProject1(c:c)(date=2023-02-01..2023-02-10)
- DAuditLogs
How the community answered
(24 responses)- A4% (1)
- B13% (3)
- C79% (19)
- D4% (1)
Why each option
To search for specific content within a date range in Microsoft Purview, the KQL query should specify the keyword, content property, and date range in the correct format.
This query has the content property `(c:c)` before the keyword `Project1`, which is not the standard or effective KQL syntax for searching keywords in content.
`AuditLogs` is a table name in Log Analytics/Sentinel, not a content search query for Microsoft Purview compliance.
The correct KQL syntax for content searches in Microsoft Purview places the keyword first, followed by the content property (c:c for content) and then the date range specification using `date=start_date..end_date`. So, `Project1(c:c)(date=2023-02-01..2023-02-10)` correctly identifies files containing "Project1" in their content within the specified date range.
`AuditLogs` is a table name in Log Analytics/Sentinel, not a content search query for Microsoft Purview compliance.
Concept tested: Microsoft Purview eDiscovery KQL syntax
Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/keyword-queries-and-search-conditions?view=o365-worldwide#search-conditions
Topics
Community Discussion
No community discussion yet for this question.