Microsoft 365 Administrator Expert MS-102 Practice Question

You are investigating an incident in the Microsoft Defender portal. From the Incidents & alerts page, you open the incident and launch Guided hunting. The first recommended KQL query returns several devices that attempted to run the same suspicious executable within the last 24 hours. You must immediately contain every affected endpoint without leaving the Guided hunting experience. Which action should you take in the query results pane to achieve this goal?

  • Select all listed devices and choose Isolate device from the Take action menu.

  • Select the devices and start a Live Response session from the Device details fly-out.

  • Export the query to CSV, then bulk-import the device IDs into an Intune dynamic group that enforces network isolation.

  • Add a unique device tag to each device so automated investigation can quarantine them on the next evaluation cycle.

Microsoft 365 Administrator Expert MS-102
Manage security and threats by using Microsoft Defender XDR
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot