MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Exhibit
KQL query:
DeviceProcessEvents
| where Timestamp > ago(7d)
| where FileName in~ ("powershell.exe", "cmd.exe")
| where ProcessCommandLine has_any ("-EncodedCommand", "-e", "-enc")
| summarize Count = count() by DeviceName, FileName
| where Count > 5Refer to the exhibit. You are analyzing a KQL query in Microsoft Defender XDR Advanced Hunting. The query returns a list of devices where PowerShell or cmd.exe with encoded commands executed more than 5 times in the last 7 days. The security team suspects that one of the devices is compromised due to excessive use of encoded commands. However, a legitimate administrative script uses encoded commands regularly. How can you refine the query to reduce false positives while still detecting potentially malicious activity?
⚠ Common exam trap
Many exam-takers choose to increase the count threshold (Option A) thinking it will reduce false positives, but this is a blunt instrument that also reduces true positives, whereas the correct approach is to use contextual filters like certificate or account exclusions to surgically remove known-good activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a filter to exclude processes signed by a trusted certificate or running under specific service accounts.
Adding a filter to exclude processes signed by a trusted certificate or running under specific service accounts directly addresses the legitimate administrative script that uses encoded commands. This refinement reduces false positives by allowing trusted, signed executables or known service accounts to bypass detection, while still flagging unsigned or anomalous encoded command executions that are more likely malicious. In Microsoft Defender XDR Advanced Hunting, you can use the `SigningCertificate` or `InitiatingProcessAccountName` fields in the KQL query to implement this exclusion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the Count threshold to 10.
Why it's wrong here
Raising the Count threshold from, say, 2 to 10 simply requires the same cmd.exe process to be seen more frequently before alerting. A legitimate script that runs on every sign-in or as a scheduled task will still exceed that higher limit, so the false positive remains. Moreover, a high threshold can suppress genuinely malicious, low-volume attacks that execute only once, reducing the detection sensitivity. The false positive arises from the query's matching logic, not from the count aggregation, so frequency tuning is a poor remedy.
- ✓
Add a filter to exclude processes signed by a trusted certificate or running under specific service accounts.
Why this is correct
Add a filter such as `where Process.Signer != 'Microsoft Corporation'` or `where AccountName !in ('svc_backup', 'svc_monitoring')` to exclude processes from known trusted sources. Many legitimate automation scripts are signed by an internal certificate authority or run under dedicated service accounts, so these allowlist-style filters reduce noise without hiding unknown or unsigned binaries. This is the correct approach because it preserves detection of suspicious, unsigned processes that lack a trustworthy signer and are not expected to run under service accounts. It targets the actual root cause: the alert currently flags benign, trusted execution as suspicious.
- ✗
Remove cmd.exe from the FileName filter.
Why it's wrong here
Deleting `cmd.exe` from the FileName filter would suppress all command-line interface activity, yet `cmd.exe` is a common living-off-the-land binary that attackers use to run scripts, download payloads, or enumerate the network. If the query no longer looks for it, you would lose visibility into legitimate security events as well as malicious use, creating a blind spot. A better remedy is to keep `cmd.exe` and exclude specific known-good instances, such as a managed service account's scheduled backup script, rather than removing the process entirely. This preserves detection of the process family while eliminating the offending false positive.
- ✗
Change the time range to 1 day instead of 7 days.
Why it's wrong here
Narrowing the time range to 1 day does not change what the query matches; it only changes how much historical data is scanned. If the benign script runs daily or every few hours, it will still appear within a 1-day window and generate the same alert. The false positive is caused by the absence of a filter on the signer or the service account, not by the length of the time range. Even worse, a shorter hunting window can miss a slow-and-steady attack that triggers only once or twice in a week, so this change actually weakens the detection without fixing the noise.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Cloud Apps Administration
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.