Exam

Microsoft Defender XDR Hunting Schema Investigation

Subject Cyber Threat Intelligence
Duration 45 mins
Passing Score 75%
Instructions

Use the official Microsoft Learn advanced-hunting schema, DeviceProcessEvents, DeviceNetworkEvents, and hunting best-practices pages. Verify column definitions rather than guessing from KQL names.

Authentication Required

You must be logged in to take this exam and record your progress.