Refer to the exhibit. A security analyst runs the KQL query in Microsoft Defender for Endpoint. The query returns no results. What is the most likely cause?
The DeviceInfo table in Microsoft Defender for Endpoint exclusively stores records for devices that have been successfully onboarded and are actively reporting sensor data. If a device has not completed the onboarding process, or if its Defender for Endpoint sensor is not functioning or reporting, no corresponding entry will exist within the DeviceInfo table. Therefore, a KQL query attempting to retrieve information for such a device would correctly return an empty result set, indicating the absence of that device's data in the platform.
Why this answer
The KQL query in Microsoft Defender for Endpoint returns no results because the device is not onboarded. Defender for Endpoint can only report on devices that have been enrolled and are actively sending telemetry. If a device is not onboarded, no data exists for it in the security portal, so any query targeting that device will return empty results.
Exam trap
The trap here is that candidates may think a missing result is due to permissions or OS incompatibility, but the core prerequisite for any Defender for Endpoint query is that the device must be onboarded and actively reporting telemetry.
How to eliminate wrong answers
Option A is wrong because a risk score of zero does not prevent a query from returning results; it simply indicates no detected threats, but the device would still appear in query results. Option B is wrong because Microsoft Defender for Endpoint supports macOS devices, and a macOS device can be onboarded and queried successfully. Option C is wrong because if the analyst lacked permissions, the query would typically return an access denied error or no results at all, but the most common and direct cause for no results when a device is known to exist is that it has never been onboarded.