Questions
The best way to learn KQL is to practice it, hands-on, in the Microsoft 365 Defender portal. But, you can also test yourself with these questions:
- True or false? You should practice actively hunting in your environment, rather than relying on automation, to stay ahead of emerging threats that may not have their own detection yet:
- True
- False
- Which is this chapter’s recommended join flavor in advanced hunting?
rightsemi
leftsemi
innerunique
fullout
- How many days back in time can you perform advanced hunting queries?
- 90 days
- 30 days
- 120 days
- 180 days
- Which of the following two options can advanced hunting data be categorized into?
- Entity data
- Cloud/on-prem data
- Automatic/manual data
- Event/activity data
- Which of the following is not an option for how often custom queries can run?
- Continuous
- Every 24 hours
- Every 48 hours
- Every 12 hours