SC-200 Respond to security incidents • Set 26
SC-200 Respond to security incidents Practice Test 26 — 15 questions with explanations. Free, no signup.
Refer to the exhibit. You run this KQL query in Microsoft Defender XDR to detect suspicious PowerShell activity. Why might this query generate many false positives?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.