Microsoft 365 Administrator Expert MS-102 Practice Question

Your SOC uses Microsoft Defender XDR. Analysts repeatedly receive the alert "Suspicious PowerShell command line" generated by a sanctioned automation script that runs nightly on 200 servers. After confirming the script is benign, you must stop further occurrences of this specific alert while keeping all other PowerShell-related detections active. What should you do from the alert details pane?

  • Add the script's file hash as an allowed indicator in Microsoft Defender for Endpoint.

  • Create an alert suppression rule for the alert's command-line pattern.

  • Resolve the incident and mark it as a false positive.

  • Configure a Microsoft Defender Antivirus exclusion for the folder that stores the script.

Microsoft 365 Administrator Expert MS-102
Manage security and threats by using Microsoft Defender XDR
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot