AB-650 Practice Question 3148
Exam: AB-650
Domain: Govern and secure Microsoft 365 tenants and workloads
Difficulty: easy
You are using Advanced Hunting in the Microsoft Defender XDR portal to search raw endpoint event logs for suspicious PowerShell activity. What query language is used?
Answer Options
A
Kusto Query Language (KQL)
B
Transact-SQL (T-SQL)
C
GraphQL syntax
D
Python scripting only
Correct Answer
A: Kusto Query Language (KQL)
Explanation
Advanced Hunting queries telemetry data across endpoints, email, and identity using Kusto Query Language (KQL).