Microsoft SC-200 Exam - Topic 2 Question 77 Discussion
You have a Microsoft 365 subscription. You have the following KQL query.DeviceEvents| where ActionType == "AntivirusDetection*You need to ensure that you can create a Microsoft Defender XDR custom detection rule by using the query.What should you add to the query?
D) sumarize (ReportId)=make_set(ReportId), count() by Deviceld
A) summarize (Timestamp, DeviceHanw)=arg_min(Timestampf DeviceName), count() by Deviceld
B) sumarize (Timestamp, ReportId)>arg_max(Timestanp, Reportld), count{) by Deviceld
C) summarize (Timestamp)=range(Timestatip), count() by Deviceld
Graciela
8 months agoDean
8 months agoEden
8 months agoAltha
9 months agoShalon
9 months agoLanie
9 months agoTawny
9 months agoMartina
9 months agoRashida
10 months agoMing
10 months agoCammy
10 months agoReena
10 months agoJenelle
10 months agoJolanda
10 months agoTwana
10 months agoKaitlyn
10 months agoLorean
1 year agoCory
1 year agoChantell
1 year agoLinwood
1 year agoSharee
1 year agoLaine
1 year agoRonny
1 year agoNickie
1 year agoDelsie
1 year agoKallie
1 year agoTonja
1 year agoClorinda
1 year agoLucia
1 year agoGeraldine
1 year agoThomasena
1 year agoDetra
1 year agoThersa
1 year agoMarta
1 year agoVon
1 year agoValene
1 year agoVeta
1 year agoTrinidad
1 year ago