正解:B
When creating custom detection rules in Microsoft Defender XDR (formerly Microsoft 365 Defender), the detection frequency determines how often the rule runs to evaluate the specified KQL query against the dataset.
In this scenario, the objective is to detect command and control (C2) agent traffic that communicates once every 50 hours (approximately every 2 days), while still covering the past 14 days of device telemetry. The requirements emphasize:
* Identifying all devices that have communicated in the past 14 days, and
* Minimizing detection latency (how quickly compromised devices are identified),while balancing query efficiency and cost.
Option
Frequency
Evaluation
A). Every 3 hours
Too frequent for agents that beacon every ~50 hours. Creates unnecessary computation and no added detection benefit.
B). Every 24 hours
Optimal. Ensures daily evaluation, aligning with Defender XDR's typical log ingestion latency and well within the 50-hour communication window. Provides timely identification without resource waste.
C). Every hour
Excessively frequent; consumes unnecessary compute resources and does not improve detection effectiveness because C2 traffic occurs only once every 50 hours.
D). Every 12 hours
Slightly faster than daily but still redundant given the 50-hour beacon interval. Adds cost without significantly reducing time to detection.
Microsoft's Defender XDR documentation states:
"For rules that identify infrequent or periodic activities, such as command-and-control communications or rare logon patterns, set the detection frequency based on the expected activity interval to minimize cost and optimize performance. For daily or multi-day behaviors, a frequency of 24 hours is recommended." Because the C2 agents communicate every 50 hours, a 24-hour detection frequency ensures the query executes often enough to detect compromised devices promptly while avoiding redundant runs or excess processing overhead.
# Final answer: B. Every 24 hours