AB-650 Practice Question 3162

Exam: AB-650
Domain: Govern and secure Microsoft 365 tenants and workloads
Difficulty: medium
Which PowerShell cmdlet is used to search Microsoft Purview unified audit logs programmatically?

Answer Options

A
Search-UnifiedAuditLog
B
Get-MailboxStatistics
C
Test-EmailFlowOrientation
D
Set-ExecutionPolicy

Correct Answer

A: Search-UnifiedAuditLog

Explanation

The Search-UnifiedAuditLog cmdlet queries the tenant unified audit log using filters for date ranges, operations, record types, and user identities.