MS-102 Practice Question 3066
Exam: MS-102
Domain: Manage security and threats using Microsoft Defender XDR
Difficulty: medium
A security operations team uses Kusto Query Language (KQL) in Microsoft Defender XDR to hunt for suspicious PowerShell execution commands across all endpoints. Which portal blade provides this capability?
Answer Options
A
Advanced Hunting in Microsoft Defender XDR
B
Exchange Admin Center Mail Flow Rules
C
Microsoft Purview eDiscovery standard export
D
Microsoft 365 Admin Center Billing history
Correct Answer
A: Advanced Hunting in Microsoft Defender XDR
Explanation
Advanced Hunting in Microsoft Defender XDR enables query-based threat hunting across up to 30 days of raw telemetry using Kusto Query Language (KQL).