Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Exhibit

Refer to the exhibit.

```kusto
// KQL query in Microsoft Defender XDR advanced hunting
DeviceProcessEvents
| where Timestamp > ago(7d)
| where FileName in~ ("powershell.exe", "cmd.exe")
| where ProcessCommandLine contains "-EncodedCommand"
| project Timestamp, DeviceName, FileName, ProcessCommandLine
| summarize Count = count() by DeviceName
| where Count > 10
```

Refer to the exhibit. You run the KQL query in advanced hunting. What is the primary purpose of this query?

⚠ Common exam trap

It's easy for candidates to confuse 'encoded commands' with 'execution policy bypass' or focus on the presence of PowerShell without recognizing that the specific '-EncodedCommand' parameter is the key indicator of obfuscation and potential malicious activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify devices with high use of encoded commands, which may indicate malicious activity

The KQL query filters for DeviceProcessEvents where the command line contains 'powershell' and the process command line includes '-EncodedCommand', which is a known technique used by attackers to obfuscate malicious scripts. The query then counts such events per device and filters for devices with more than 10 occurrences, indicating a high volume of encoded PowerShell commands that may signal malicious activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Identify devices with outbound connections to malicious IPs

    Why it's wrong here

    The query inspects local device configuration and process data rather than correlating outbound network traffic against threat intelligence, so no IP reputation lookup occurs. It is tempting because malicious outbound connections are a frequent hunting goal, and would be correct if the query joined DeviceNetworkEvents with an IP address indicator table.

  • ✗

    Identify devices with PowerShell execution policy set to bypass

    Why it's wrong here

    The query filters on network connection events, not on device configuration or script execution settings, so it cannot surface PowerShell execution policy values. It is tempting because bypass execution policy is a common attacker technique, and would be correct if the query inspected DeviceRegistryEvents or DeviceProcessEvents for that setting.

  • ✗

    Identify devices where a user deleted system files using cmd

    Why it's wrong here

    The query does not parse command-line arguments for file deletion commands such as del or erase, so it cannot detect removal of system files. It is tempting because destructive cmd activity is a genuine hunting scenario, and would be correct if the query filtered DeviceProcessEvents on cmd.exe command lines containing those deletion verbs.

  • ✓

    Identify devices with high use of encoded commands, which may indicate malicious activity

    Why this is correct

    The query aggregates encoded command usage per device, so its purpose is surfacing endpoints whose PowerShell or shell activity is heavily encoded. High encoded-command counts frequently indicate obfuscated malicious execution, making this a threat-hunting signal rather than a compliance or inventory check.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.