MS-102 Manage security and threats by using Microsoft Defender XDR • Set 12
MS-102 Manage security and threats by using Microsoft Defender XDR Practice Test 12 — 15 questions with explanations. Free, no signup.
A security analyst is creating a custom detection rule in Microsoft 365 Defender Advanced Hunting. The rule should trigger when a device makes an outbound connection to a known malicious IP address, and within 10 minutes, a process with suspicious command-line arguments is started on the same device. Which two Advanced Hunting tables must be joined using a KQL query to create this detection?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.