exam questions

Exam MS-101 All Questions

View all questions & answers for the MS-101 exam

Exam MS-101 topic 2 question 9 discussion

Actual exam question from Microsoft's MS-101
Question #: 9
Topic #: 2
[All MS-101 Questions]

Your company has 5,000 Windows 10 devices. All the devices are protected by using Microsoft Defender Advanced Threat Protection (ATP).
You need to create a filtered view that displays which Microsoft Defender ATP alert events have a high severity and occurred during the last seven days.
What should you use in Microsoft Defender ATP?

  • A. the threat intelligence API
  • B. Automated investigations
  • C. Threat analytics
  • D. Advanced hunting
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
arai002
Highly Voted 3 years, 9 months ago
The important thing is you need create fileter or not Topic4 Question #29 ASK:You want to display Microsoft Defender ATP alert events ***you don't need create filter**** ANS:B:Automated investigations Topic2 Qutstion#8 ASK:You need to create a filtered view that displays which Microsoft Defender ATP alert ****you need create ***** ANS:D:Advanced hunting Advanced hunting can create query and filter For example: DeviceAlertEvents | where Severity == "high" | where Timestamp > ago(7d)
upvoted 32 times
...
MiZi
Highly Voted 3 years, 11 months ago
As I see, the answer should be D. Advanced Hunting. You can query anything there like in the Azure Log Analytics. Automated Investigations can give the 7day (1 week) view, but do not show severity. Please correct me if I am wrong here.
upvoted 24 times
...
encxorblood
Most Recent 2 years, 3 months ago
B - You need Automated investigations to see alerts
upvoted 1 times
...
[Removed]
2 years, 5 months ago
I'm going with Automated Investigation. The link Exam Topics provides a video. Starting at the 2 minute mark, the video even mentions "filtering" days, computer names, etc. within the Automated Investigation app: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/automated-investigations?view=o365-worldwide At 2:12 "...and of course, filter the list..."
upvoted 3 times
...
gmKK
2 years, 7 months ago
Likely outdated question since this view is available under alerts: https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/alerts-queue?view=o365-worldwide
upvoted 4 times
RenegadeOrange
2 years, 7 months ago
Agree if its in the exam now one of the solutions will be the "Alerts" section which shows you that stuff by default and allows you to filter. Alternatively it's possible but much more work in Advanced Hunting.
upvoted 1 times
...
...
ijskoe
2 years, 8 months ago
Selected Answer: D
as per ms doc
upvoted 1 times
...
ale2197
2 years, 10 months ago
Selected Answer: D
as other user are telling... D
upvoted 2 times
...
DARKK
3 years ago
Selected Answer: D
D advanced Hunting
upvoted 3 times
...
JamesM9
3 years, 1 month ago
The answer is B – Automated Investigations, as per the link below (last updated March 25, 2022) https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/alerts-queue?view=o365-worldwide
upvoted 5 times
...
ScottT
3 years, 1 month ago
2 mins in to video in https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/automated-investigations?view=o365-worldwide has the answer. The answer is B
upvoted 1 times
...
TashaGirl
3 years, 1 month ago
There is no correct answer here. Updated docs: https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/alerts-queue?view=o365-worldwide
upvoted 1 times
...
LillyLiver
3 years, 2 months ago
This is a tough one, and I think that the question answers are out of date. Automated Investigations doesn't seem to be an option in the admin portal anymore (as of 2/20/2022). I'm going with D. Advanced Hunting.
upvoted 1 times
...
larnyx
3 years, 8 months ago
Should most surely be, D. Advanced hunting allows you to create a query that proccesses 30 days of raw data and outputs the info asked for. Automated investigations handles itself by starting a scan once alerted and remidiates the issue at hand.
upvoted 3 times
...
gkp_br
3 years, 9 months ago
"D. Advanced hunting". I cant find that filter in Automated investigations blade.
upvoted 3 times
...
arai002
3 years, 9 months ago
D: Advanced hunting Question sed "You need to create" Automated investigations can only filter Advanced hunting can create query and filter For example: DeviceAlertEvents | where Severity == "high" | where Timestamp > ago(7d) That's why Correct Answer : D
upvoted 7 times
LoremanReturns
3 years, 9 months ago
I agree. Automated investigation is used to automate response to specific detection. The answer asks to report specific detections that can be achieved with Advanced Hunting
upvoted 3 times
...
...
Pawnzy
3 years, 10 months ago
I think B. Automated investigations is correct because it is asking for a filtered view from something like the Alert Queue rather than creating a query to look for the data then filter
upvoted 3 times
...
Jake1
4 years ago
Automated Investigations is correct. https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/automated-investigations?view=o365-worldwide.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago