AB-650 Practice Question 3148

Exam: AB-650
Domain: Govern and secure Microsoft 365 tenants and workloads
Difficulty: easy
You are using Advanced Hunting in the Microsoft Defender XDR portal to search raw endpoint event logs for suspicious PowerShell activity. What query language is used?

Answer Options

A
Kusto Query Language (KQL)
B
Transact-SQL (T-SQL)
C
GraphQL syntax
D
Python scripting only

Correct Answer

A: Kusto Query Language (KQL)

Explanation

Advanced Hunting queries telemetry data across endpoints, email, and identity using Kusto Query Language (KQL).