Your Microsoft Defender XDR environment has an advanced hunting query that returns devices potentially affected by a known vulnerability. You want to create a custom detection rule that triggers an alert when more than 10 devices are affected. Which THREE steps are required?
In Microsoft Defender XDR custom detection rules, you must set both the rule frequency (how often the query runs, such as every hour) and the threshold (the number of results that triggers the rule) in the rule's settings. For this scenario, configuring the threshold to fire when the query returns more than 10 results ensures that only significant matches generate alerts, reducing false positives. This step is essential because without a defined frequency and threshold, the rule has no scheduling or triggering condition to act on.
Why this answer
Setting the rule frequency and threshold to trigger when the query returns more than 10 results directly implements the requirement to alert when more than 10 devices are affected. In Microsoft Defender XDR custom detection rules, the threshold condition is configured in the rule settings to evaluate the number of query results against a specified count, enabling precise alert triggering based on result volume.
Exam trap
The trap here is that candidates often confuse optional post-alert actions (like Power Automate flows or severity assignment) with the mandatory steps required to create a functional custom detection rule, leading them to select options C or D instead of focusing on the core rule creation steps (save query, set frequency/threshold, configure alert action).