Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Exhibit

Refer to the exhibit.

```kusto
DeviceEvents
| where Timestamp > ago(7d)
| where ActionType == "AntivirusDetection"
| where FileName has_any ("ransomware", "encrypt")
| summarize ThreatCount = count() by DeviceName
| top 10 by ThreatCount
```

A security analyst runs the above KQL query in Microsoft 365 Defender. The query returns an empty result set. Which is the most likely reason?

⚠ Common exam trap

MS-102 often tests whether candidates confuse an empty query result with a query error or misconfiguration, when in fact the absence of matching events is the correct interpretation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

No antivirus detection events for files with 'ransomware' or 'encrypt' in the filename occurred in the last 7 days.

The KQL query filters DeviceEvents for antivirus detection events where the filename contains 'ransomware' or 'encrypt' within the last 7 days. An empty result set simply means no such events matched the filter criteria during that period — this is a normal, expected outcome when no ransomware-like files were detected, not an error condition. The query syntax and table are valid; the absence of data is the answer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The time range is too wide and the query times out.

    Why it's wrong here

    A 7-day lookback is not an unusually wide time range for Microsoft 365 advanced hunting; DeviceEvents queries can efficiently scan up to 30 days of data. The query's low result count indicates it completed without hitting the 10-minute timeout. If a timeout did occur, it would likely stem from missing early filters or overly broad projections, not the time range itself.

  • ✓

    No antivirus detection events for files with 'ransomware' or 'encrypt' in the filename occurred in the last 7 days.

    Why this is correct

    The query returned zero rows because no antivirus detection events with a filename containing the exact term 'ransomware' or 'encrypt' were logged in the last 7 days. This is a valid, actionable result; it does not mean the query is flawed. To uncover broader suspicious activity, reduce reliance on the filename term match or use contains for substring matching, and consider expanding the time range or adding related tables like DeviceFileEvents.

  • ✗

    The 'has_any' operator is used incorrectly; it should be 'contains' for each condition.

    Why it's wrong here

    The has_any operator is a valid KQL function that searches for multiple terms in a string and is case-insensitive; it works correctly here. Unlike contains, which performs substring matching, has_any matches whole terms delimited by non-alphanumeric characters — so 'ransomware.exe' would match, but 'myransomwarefile' would not. The choice between has_any and contains affects recall, but using has_any is not an error that would invalidate the query.

  • ✗

    The DeviceEvents table does not contain antivirus detection events.

    Why it's wrong here

    In the Microsoft 365 Defender advanced hunting schema, the DeviceEvents table is exactly where security events, including antivirus detections, are stored. Rows with ActionType values like AntivirusDetection are common in this table and are surfaced by default. Therefore, the table is a legitimate source for antivirus detections, and zero results are due to the filter criteria, not table selection.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.