AB-650 Practice Question 3162
Exam: AB-650
Domain: Govern and secure Microsoft 365 tenants and workloads
Difficulty: medium
Which PowerShell cmdlet is used to search Microsoft Purview unified audit logs programmatically?
Answer Options
A
Search-UnifiedAuditLog
B
Get-MailboxStatistics
C
Test-EmailFlowOrientation
D
Set-ExecutionPolicy
Correct Answer
A: Search-UnifiedAuditLog
Explanation
The Search-UnifiedAuditLog cmdlet queries the tenant unified audit log using filters for date ranges, operations, record types, and user identities.