MS-102 Practice Question 3066

Exam: MS-102
Domain: Manage security and threats using Microsoft Defender XDR
Difficulty: medium
A security operations team uses Kusto Query Language (KQL) in Microsoft Defender XDR to hunt for suspicious PowerShell execution commands across all endpoints. Which portal blade provides this capability?

Answer Options

A
Advanced Hunting in Microsoft Defender XDR
B
Exchange Admin Center Mail Flow Rules
C
Microsoft Purview eDiscovery standard export
D
Microsoft 365 Admin Center Billing history

Correct Answer

A: Advanced Hunting in Microsoft Defender XDR

Explanation

Advanced Hunting in Microsoft Defender XDR enables query-based threat hunting across up to 30 days of raw telemetry using Kusto Query Language (KQL).