Microsoft 365 Administrator Expert MS-102 Practice Question
You are investigating an incident in the Microsoft Defender portal. From the Incidents & alerts page, you open the incident and launch Guided hunting. The first recommended KQL query returns several devices that attempted to run the same suspicious executable within the last 24 hours. You must immediately contain every affected endpoint without leaving the Guided hunting experience. Which action should you take in the query results pane to achieve this goal?
Select all listed devices and choose Isolate device from the Take action menu.
Select the devices and start a Live Response session from the Device details fly-out.
Export the query to CSV, then bulk-import the device IDs into an Intune dynamic group that enforces network isolation.
Add a unique device tag to each device so automated investigation can quarantine them on the next evaluation cycle.
Guided hunting opens the Advanced hunting interface pre-populated with investigation queries scoped to entities in the incident. Results returned by any of these queries support the same entity-level response actions that are available in standard Advanced hunting. For device entities, selecting the relevant rows and choosing Isolate device from the Take action menu immediately contains the endpoints by blocking all inbound and outbound network traffic except those connections required for Defender communication. The other options either do not exist in the Guided hunting results pane (running Live Response session directly, moving devices to an Intune group) or cannot initiate containment (adding a device tag is only a labeling operation).
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Guided hunting in Microsoft Defender?
Open an interactive chat with Bash
What does the 'Isolate device' action do in Microsoft Defender?
Open an interactive chat with Bash
How does Advanced Hunting complement Guided hunting in Microsoft Defender?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Manage security and threats by using Microsoft Defender XDR
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .