MS-102 Manage security and threats by using Microsoft Defender XDR • Set 17
MS-102 Manage security and threats by using Microsoft Defender XDR Practice Test 17 — 15 questions with explanations. Free, no signup.
A security analyst wants to create a custom detection rule that triggers when a device communicates with a new, unclassified IP address that has been flagged by Microsoft threat intelligence as potentially malicious. The rule should run every hour and create an incident if more than 5 such communications from the same device occur within a 24-hour window. Which advanced hunting tables should be joined in the KQL query for this rule?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.