Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft MS-102 Exam - Topic 3 Question 62 Discussion

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.All the devices in your organization are onboarded to Microsoft Defender for Endpoint.You need to ensure that an alert is generated if malicious activity was detected on a device during the last 24 hours.What should you do?
C) From Advanced hunting, create a query and a detection rule.
A) From the Microsoft Purview compliance portal, create a data loss prevention (DLP) policy.
B) From Alerts queue, create a suppression rule and assign an alert.
D) From the Microsoft Purview compliance portal, create an audit log search.

Microsoft MS-102 Exam - Topic 3 Question 62 Discussion

Actual exam question for Microsoft's MS-102 exam
Question #: 62
Topic #: 3
[All MS-102 Questions]

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.

All the devices in your organization are onboarded to Microsoft Defender for Endpoint.

You need to ensure that an alert is generated if malicious activity was detected on a device during the last 24 hours.

What should you do?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Adelle
3 days ago
Not sure about that, DLP policies don’t seem relevant here.
upvoted 0 times
...
Ruth
8 days ago
I think option C is definitely the way to go.
upvoted 0 times
...
Alaine
13 days ago
You need to use Advanced hunting for that!
upvoted 0 times
...
Glory
18 days ago
The DLP policy option seems off for this scenario; I don't think it relates to detecting malicious activity directly.
upvoted 0 times
...
Alline
23 days ago
I feel like creating a detection rule is the right approach, but I can't recall the exact steps to do that in Advanced hunting.
upvoted 0 times
...
Antonio
29 days ago
I remember practicing with suppression rules, but I don't think that's what we need here since we want to generate an alert.
upvoted 0 times
...
Giovanna
1 month ago
I think we might need to use Advanced hunting for this one, but I'm not entirely sure how to set up the query correctly.
upvoted 0 times
...

Save Cancel