Microsoft SC-200 Exam - Topic 2 Question 77 Discussion
You have a Microsoft 365 subscription. You have the following KQL query.DeviceEvents| where ActionType == "AntivirusDetection*You need to ensure that you can create a Microsoft Defender XDR custom detection rule by using the query.What should you add to the query?
D) sumarize (ReportId)=make_set(ReportId), count() by Deviceld
A) summarize (Timestamp, DeviceHanw)=arg_min(Timestampf DeviceName), count() by Deviceld
B) sumarize (Timestamp, ReportId)>arg_max(Timestanp, Reportld), count{) by Deviceld
C) summarize (Timestamp)=range(Timestatip), count() by Deviceld
Graciela
10 months agoDean
10 months agoEden
10 months agoAltha
10 months agoShalon
10 months agoLanie
11 months agoTawny
11 months agoMartina
11 months agoRashida
11 months agoMing
11 months agoCammy
11 months agoReena
11 months agoJenelle
11 months agoJolanda
11 months agoTwana
12 months agoKaitlyn
12 months agoLorean
1 year agoCory
1 year agoChantell
1 year agoLinwood
1 year agoSharee
1 year agoLaine
1 year agoRonny
1 year agoNickie
1 year agoDelsie
1 year agoKallie
1 year agoTonja
1 year agoClorinda
1 year agoLucia
1 year agoGeraldine
1 year agoThomasena
1 year agoDetra
1 year agoThersa
1 year agoMarta
1 year agoVon
1 year agoValene
1 year agoVeta
1 year agoTrinidad
1 year ago