Read the short answer first, then explain the example without reading. Complete the practice task and collect evidence. The 50/40/30/20-question counts follow twice the higher estimates in your table; they are a preparation target, not a guaranteed employer question bank.
Pehle short answer parho, phir example apni zubaan mein samjhao. Practice task complete karke evidence rakho. Answers ratta laganay ke bajaye steps aur reasoning samjho.
Lab requirements: Connected Sentinel workspace or authorised training lab, populated test data, suitable reader/analyst permissions. Automation practice needs supported Logic Apps connectors and permissions. Azure services can incur charges; plan the lab budget and stop unused resources.
Course outcomes / Aap kya kar saken ge
Beginner
SIEM, workspace, connector and entity concepts
KQL filters, selected columns and counts
Simple incident triage and documented classification
Simple incident investigate karke classification document karo
Intermediate
Join and aggregate telemetry with justified time windows
Design and test a scheduled detection with mapped entities
Investigate a multi-source incident and assess false positives
Build a basic enrichment workflow and diagnose failures
Tables ko justified timing ke saath join karo
Detection test aur entity mapping verify karo
Multi-source incident aur false positives investigate karo
Basic enrichment workflow aur failure troubleshoot karo
Learning path and practice schedule
This is a suggested 132-hour topic plan: 36 beginner hours plus 96 additional intermediate hours. At 4–6 hours a day, allow approximately 6–9 study days for the beginner stage and 22–33 study days total for this guided course. These are planning estimates, not promises of independent workplace competence. Repeat stages if the practical checkpoints are weak. Related subjects overlap in the combined plan.
Daily routine: 4–6 hours
Activity
Core 4 hours
Optional extra 2 hours
Concepts and official tutorial
60 minutes
—
Hands-on lab or evidence exercise
120 minutes
90 minutes: a harder case or failed scenario
Interview answers aloud
30 minutes
30 minutes: mock interview and follow-ups
Review and evidence log
30 minutes
—
Roman Urdu: Roz aik ghanta concepts, do ghantay practical, aadha ghanta answers bol kar aur aadha ghanta review karo. Extra do ghantay hon to difficult lab aur mock interview karo. Har haftay chhay study days aur aik rest/catch-up day rakho.
Study time means focused work, excluding breaks. Allocate at least half to practical work. If no tenant or lab is available, analyse supplied data and diagrams, but record that limitation and revisit the task when you have access.
Stage and time
Direction and practice
Resource / tutorial
Deliverable in Roman Urdu
1. Beginner 12 hours 2–3 study days
Foundations and data flow
Read the overview and configuration path; map two log sources, their destination tables and prerequisites.
Complete scenario, report aur mock interview repeat karo.
Practical exit check
Beginner: Complete a basic task using documentation, explain the result and recognise when to escalate.
Intermediate: Complete a common scenario without a step-by-step answer, justify your checks, test an alternative explanation and verify the result. You may consult references as analysts do at work.
Beginner par documentation ke saath basic task karo. Intermediate par ready-made steps ke baghair scenario solve, reasoning explain aur result verify karo.
Visual explanations
Original concept diagram. The three inputs on the left contribute to the central investigation or assessment, supporting the decision on the right. Relationships are conceptual, not a screenshot or an exhaustive deployment architecture.
Left ki information central analysis mein use hoti hai, phir decision ya response support hota hai.
Example troubleshooting decision. Use the branch that matches the observed evidence; complete verification after any corrective action.
Evidence ke mutabiq Yes ya No branch choose karo. Action ke baad result verify karo.
50 interview questions
Level labels indicate study focus, not a formal certification standard. Each short answer is a starting point for a 30–60 second response; expand with the example and your own honest experience.
A cloud SIEM with automation capabilities for detecting, investigating and responding to threats.
Why this matters · English explanation
It combines security telemetry from different sources so analysts can examine related activity.
Roman Urdu explanation
Sentinel mukhtalif systems ke logs jama karke threat detect aur investigate karne mein madad karta hai.
Worked context / illustrative example
Failed cloud logins and suspicious endpoint activity can be investigated together.
Your practical task
Draw the journey from log source to incident.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
SIEM analyses security events; SOAR orchestrates and automates response workflows.
Why this matters · English explanation
Detection and response are related, but collecting a log does not automatically trigger an action.
Roman Urdu explanation
SIEM logs analyse karta hai; SOAR response ke mukhtalif steps automatically chalata hai.
Worked context / illustrative example
A detection identifies suspicious activity; a playbook enriches the IP and opens a ticket.
Your practical task
Explain one detection and one automated response.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
A container for Azure Monitor log data and associated configuration.
Why this matters · English explanation
Workspace design affects access, retention, data separation and cost; Sentinel uses workspace-based log analytics for relevant data.
Roman Urdu explanation
Workspace logs aur unki settings ka container hai. Access aur retention bhi plan karni hoti hai.
Worked context / illustrative example
A training workspace receives sign-in logs from a test tenant.
Your practical task
List the data, access and retention needs of a lab.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Connector prerequisites, collection methods and table destinations differ; validate actual records rather than assuming installation means ingestion works.
Roman Urdu explanation
Connector data source ko Sentinel se jorta hai. Install ke baad actual logs check karna zaroori hai.
Worked context / illustrative example
A sign-in connector is configured but permissions prevent collection.
Your practical task
Identify prerequisites for one supported connector.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Install a solution, then configure its connector and enable a suitable rule.
Your practical task
List the components of one solution.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Detection logic that evaluates data and can generate alerts.
Why this matters · English explanation
Scheduled rules use a query, time settings and thresholds; incident creation and entity mapping require suitable configuration.
Roman Urdu explanation
Analytics rule suspicious pattern dhoondti hai. Query, timing aur threshold sahi set karne hote hain.
Worked context / illustrative example
Detect repeated unsuccessful sign-ins within a defined period.
Your practical task
Write the logic and expected false positives first.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
An alert flags a detection; an incident groups related evidence for investigation.
Why this matters · English explanation
One incident can contain multiple alerts, so review the whole attack story rather than one notification.
Roman Urdu explanation
Alert aik detection hai; incident related alerts aur evidence ka investigation case hai.
Worked context / illustrative example
A suspicious login and later privilege change are reviewed in one incident.
Your practical task
Explain why one alert may be insufficient.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Recognised investigation objects such as accounts, hosts and IP addresses.
Why this matters · English explanation
Entity mapping connects query fields to those objects so analysts can pivot between related evidence.
Roman Urdu explanation
Entities user, device ya IP jaisi cheezen hain jin par investigation pivot karti hai.
Worked context / illustrative example
Map UserPrincipalName to an account entity and IPAddress to an IP entity.
Your practical task
Identify entity fields in a sample query.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Searching, transforming and aggregating telemetry.
Why this matters · English explanation
KQL log queries read data; their output depends on the selected table, schema, time range and access rights.
Roman Urdu explanation
KQL se logs search, filter aur count karte hain. Table aur time range sahi honi chahiye.
Worked context / illustrative example
Search SigninLogs for one user before counting unsuccessful attempts.
Your practical task
Explain a query one operator at a time.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Match the investigation question to the available telemetry and inspect the schema.
Why this matters · English explanation
Similar-looking events may live in different tables with different field names.
Roman Urdu explanation
Pehle dekho required event kis table mein hai, phir us ke columns check karo.
Worked context / illustrative example
Cloud sign-ins use SigninLogs when that data is connected; host events need other tables.
Your practical task
Inspect five columns in an available table.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Combine a narrow time range with a relevant condition to reduce irrelevant data.
Roman Urdu explanation
Where sirf woh records rakhta hai jo condition poori karte hain.
Worked context / illustrative example
SigninLogs
| where TimeGenerated > ago(1h)
| where UserPrincipalName == "user@example.com"
Your practical task
Change the user and explain both filters.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
It aggregates rows into counts or other statistics.
Why this matters · English explanation
Grouping determines what each result represents; counting by user differs from counting by user and IP.
Roman Urdu explanation
Summarize logs ka count ya summary banata hai. Grouping badlay to result ka matlab bhi badalta hai.
Worked context / illustrative example
SigninLogs
| summarize Attempts=count() by UserPrincipalName
Your practical task
Compare a per-user count with a per-IP count.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Filter SigninLogs for a recent period and ResultType not equal to "0".
Why this matters · English explanation
These are unsuccessful events, not automatic proof of password attacks.
Roman Urdu explanation
ResultType zero ke ilawa unsuccessful sign-in hai. Har failure attack nahin hota.
Worked context / illustrative example
SigninLogs
| where TimeGenerated > ago(24h)
| where ResultType != "0"
| summarize Attempts=count() by UserPrincipalName, IPAddress
Your practical task
Add a threshold and explain its limitations.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
It groups values into intervals such as five-minute time buckets.
Why this matters · English explanation
Fixed buckets are not sliding windows and can split a burst across boundaries.
Roman Urdu explanation
Bin time ko chotay intervals mein group karta hai. Boundary par aik burst do groups mein aa sakta hai.
Worked context / illustrative example
SigninLogs
| summarize Attempts=count() by bin(TimeGenerated, 5m), IPAddress
Your practical task
Explain how bucket boundaries affect detection.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Join combines rows using matching keys; union stacks compatible result sets.
Why this matters · English explanation
Choose a join type carefully and watch for duplicated rows or missing matches.
Roman Urdu explanation
Join matching key par tables jorta hai; union records aik result mein jama karta hai.
Worked context / illustrative example
Join an account event with another table using a consistently normalised user identifier.
Your practical task
Sketch leftouter and inner results using three sample rows.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Prefer existing structured columns; test missing fields and unexpected formats when parsing is necessary.
Roman Urdu explanation
Text ke andar se field nikalne ke liye parse ya extract use hota hai.
Worked context / illustrative example
Extract an account value from a fictional custom log message.
Your practical task
Test a matching, nonmatching and empty message.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Use consistent identifiers and understand that display names are not always unique.
Roman Urdu explanation
Username ka case ya format different ho to join miss ho sakta hai. Unique identifier behtar hota hai.
Worked context / illustrative example
user@example.com and USER@example.com need consistent treatment in a matching operation.
Your practical task
Describe a collision caused by using display names.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Wrong time range, missing data, incorrect table or field, restrictive filters or insufficient access.
Why this matters · English explanation
Test a small base query, then add filters one at a time.
Roman Urdu explanation
No result par time range, table, data aur permissions check karo. Filters aik aik karke lagao.
Worked context / illustrative example
A query uses the last hour, but the sample data is from yesterday.
Your practical task
Write a five-step no-results checklist.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Reduce time and rows early, select necessary data and avoid unnecessary expensive operations.
Why this matters · English explanation
Measure performance rather than assuming a shorter query is always faster.
Roman Urdu explanation
Pehle relevant time aur records filter karo. Query ki performance measure bhi karo.
Worked context / illustrative example
Filter before a large join and select only required columns.
Your practical task
Compare two logically equivalent lab queries.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Review severity, affected assets, evidence, timeline and business impact; establish ownership and next actions.
Why this matters · English explanation
Severity helps prioritisation, but a critical asset can change operational urgency.
Roman Urdu explanation
Severity ke saath affected asset aur business impact bhi dekho. Owner aur next action clear karo.
Worked context / illustrative example
A medium alert on a critical server may need urgent review.
Your practical task
Write a triage note with facts and open questions.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Review failed and successful sign-ins, targeted accounts, IPs, timing and authentication results.
Why this matters · English explanation
Distinguish malicious attempts from user mistakes or applications with outdated credentials.
Roman Urdu explanation
Failures, successful login, users aur IPs compare karo. Old password wali application bhi failures bana sakti hai.
Worked context / illustrative example
Twenty failures followed by a successful login require further verification.
Your practical task
Explain three legitimate and three suspicious indicators.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Spraying tries a few passwords across many accounts; brute force concentrates many guesses on a target.
Why this matters · English explanation
Detection grouping should match the behaviour, not just count all failures together.
Roman Urdu explanation
Spraying bohat users par chand passwords try karta hai; brute force aik target par bohat guesses karta hai.
Worked context / illustrative example
One IP targets fifty users with two attempts each.
Your practical task
Design a lab query counting distinct targeted users.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
No; investigate network routing, VPNs, locations, devices and surrounding events.
Why this matters · English explanation
Geolocation is a clue, not a reliable record of a person's physical location.
Roman Urdu explanation
Impossible travel clue hai, final proof nahin. VPN aur location accuracy bhi check karo.
Worked context / illustrative example
A company VPN makes a UK employee appear abroad.
Your practical task
List evidence that would strengthen the compromise hypothesis.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Correlate its activity with account and device evidence, reputation and known business use.
Why this matters · English explanation
An IP reputation result alone does not establish compromise; shared addresses can affect attribution.
Roman Urdu explanation
IP reputation ke saath actual activity aur business use check karo. Shared IP ki attribution mushkil hoti hai.
Worked context / illustrative example
An unfamiliar IP belongs to an approved remote access service.
Your practical task
Document supporting and conflicting evidence.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
How do you investigate a phishing-related incident?
Short interview answer · English
Establish recipients, message identifiers, links, clicks and any subsequent endpoint or identity activity.
Why this matters · English explanation
Use appropriate connected telemetry and coordinate email response with the authorised team.
Roman Urdu explanation
Recipients, link clicks aur baad ki device ya login activity joro. Email team se coordinate karo.
Worked context / illustrative example
A click is followed by a suspicious login for the same user.
Your practical task
Build a fictional timeline with three evidence sources.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
When impact, confidence, scope, required authority or specialist needs exceed my remit.
Why this matters · English explanation
Provide evidence, actions already taken, affected assets and a clear request.
Roman Urdu explanation
Jab impact ya required action meri authority se bahar ho to evidence ke saath escalate karunga.
Worked context / illustrative example
Suspected compromise of a privileged account requires urgent escalation.
Your practical task
Write a concise escalation message without claiming certainty.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
A legitimate administrator activity is verified and documented before closure.
Your practical task
Write a closure note for a benign activity scenario.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
An authorised simulation triggers a real suspicious-behaviour rule.
Your practical task
Explain the distinction without relying only on alert severity.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Review samples, identify legitimate patterns and adjust scope or logic while testing detection coverage.
Why this matters · English explanation
Broad exclusions reduce noise but can hide attacks; document why each exception exists.
Roman Urdu explanation
Noise ki wajah samjho, phir limited tuning karo. Bara exclusion attack chhupa sakta hai.
Worked context / illustrative example
Exclude a validated service pattern rather than every event from an entire subnet.
Your practical task
Compare detections before and after one lab change.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Use baseline behaviour, asset sensitivity, attack patterns and observed false positives.
Why this matters · English explanation
Thresholds are environment-specific; a number from a tutorial is only a starting point.
Roman Urdu explanation
Threshold normal activity aur risk dekh kar set hota hai. Tutorial ka number final standard nahin.
Worked context / illustrative example
Ten failures in a day may be common; a burst against an admin account is more concerning.
Your practical task
Propose a threshold and explain the trade-off.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
The period determines how far a scheduled rule looks back; frequency determines how often it runs.
Why this matters · English explanation
Overlapping periods and ingestion delays influence duplicates and missed events.
Roman Urdu explanation
Period pichlay kitnay logs dekhta hai; frequency rule kitni dair baad chalti hai.
Worked context / illustrative example
A rule runs every five minutes and searches a longer lookback window.
Your practical task
Draw two overlapping evaluation windows.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Delay between the event occurring and becoming available for analysis.
Why this matters · English explanation
Differentiate event time from ingestion time and account for late arrival in detection design.
Roman Urdu explanation
Event aur log available honay ke darmiyan delay ingestion latency hai.
Worked context / illustrative example
A delayed network log arrives after the shortest rule window has passed.
Your practical task
Explain how to diagnose late data without changing event timestamps.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
To associate returned fields with meaningful account, host or IP entities.
Why this matters · English explanation
Correct mappings support investigation pivots; wrong identifiers can produce misleading relationships.
Roman Urdu explanation
Sahi entity mapping related user, host aur IP par pivot mein madad karti hai.
Worked context / illustrative example
Map a real account identifier rather than a nonunique display name.
Your practical task
Check mappings against three query result rows.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
A condition-based way to manage incidents and trigger supported actions.
Why this matters · English explanation
It can assign, tag or invoke playbooks depending on configuration; order and conditions matter.
Roman Urdu explanation
Automation rule condition par incident assign, tag ya playbook trigger kar sakti hai.
Worked context / illustrative example
Tag an incident category and route it to a suitable team.
Your practical task
Design one rule without destructive response actions.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Look up an IP, add context to an incident and notify a test mailbox.
Your practical task
Sketch the workflow and a failed-lookup branch.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
The rule decides when an action runs; the playbook implements a workflow.
Why this matters · English explanation
Simple incident-management actions may not require a separate playbook.
Roman Urdu explanation
Rule batati hai kab action ho; playbook batata hai workflow mein kya steps hon.
Worked context / illustrative example
A high-priority incident condition triggers an enrichment workflow.
Your practical task
Explain why assigning an owner may need only a rule.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Check trigger conditions, run history, failed actions, connector authentication and permissions.
Why this matters · English explanation
Separate a workflow that never started from one that started and failed midway.
Roman Urdu explanation
Pehle dekho trigger chala ya nahin; phir run history, credentials aur permissions check karo.
Worked context / illustrative example
A workflow starts but its incident update action receives access denied.
Your practical task
Write separate checklists for no trigger and failed action.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Proactive investigation of a threat hypothesis using available evidence.
Why this matters · English explanation
Hunting is not limited to alerts; record the hypothesis, data coverage, findings and limitations.
Roman Urdu explanation
Hunting mein hypothesis bana kar logs mein evidence dhoondte hain, sirf alerts ka wait nahin karte.
Worked context / illustrative example
Hunt for unusual administrative sign-ins outside the established baseline.
Your practical task
Write one hypothesis and an alternative explanation.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
A saved investigation finding with relevant query context and evidence.
Why this matters · English explanation
Useful notes explain why the result matters and how another analyst can reproduce it.
Roman Urdu explanation
Bookmark important finding aur query context save karta hai. Reason likhna bhi zaroori hai.
Worked context / illustrative example
Save a suspicious account-event result with the time range and investigation note.
Your practical task
Draft a reproducible bookmark description.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
A reference dataset used to enrich or filter investigations and detections.
Why this matters · English explanation
Ownership, freshness and matching keys matter; stale exceptions can create blind spots.
Roman Urdu explanation
Watchlist reference data hai. Owner, latest update aur matching key sahi honi chahiye.
Worked context / illustrative example
Compare observed accounts with a maintained list of privileged accounts.
Your practical task
Create a fictional list and define its review schedule.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Show failed sign-ins by time and user for operational review.
Your practical task
Define three useful metrics and their limitations.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
User and entity behaviour analytics that adds behavioural context.
Why this matters · English explanation
Anomalies need investigation because unusual behaviour can also be legitimate.
Roman Urdu explanation
UEBA user aur entity ke unusual behaviour ka context deta hai. Unusual ka matlab hamesha malicious nahin.
Worked context / illustrative example
An administrator changes working hours during an approved maintenance window.
Your practical task
List context needed before treating an anomaly as malicious.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
As a vocabulary for attacker tactics and techniques when describing detection coverage.
Why this matters · English explanation
A technique mapping explains behaviour; it does not prove that an entire attack chain is covered.
Roman Urdu explanation
MITRE ATT&CK attack behaviour ko classify karne mein madad deta hai. Mapping full coverage ki guarantee nahin.
Worked context / illustrative example
Describe credential guessing separately from later lateral movement.
Your practical task
Map a scenario to behaviour and identify missing telemetry.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Check source generation, connector status, configuration, permissions, network path, destination table and time range.
Why this matters · English explanation
Identify the first broken stage instead of repeatedly rewriting the detection query.
Roman Urdu explanation
Source se workspace tak har stage check karo taake missing logs ki asal wajah milay.
Worked context / illustrative example
The source sends events, but the ingestion configuration points to another workspace.
Your practical task
Draw a troubleshooting checklist from source to query.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Understand ingestion volume, table plans, retention and query patterns; remove unnecessary duplication without losing required evidence.
Why this matters · English explanation
Set a budget and measure before changing collection scope.
Roman Urdu explanation
Data volume, retention aur duplicate collection check karo. Cost kam karte waqt required evidence na kho do.
Worked context / illustrative example
Verbose low-value logs dominate ingestion while essential authentication data is small.
Your practical task
Produce a lab cost checklist rather than a price promise.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
Apply least privilege, suitable roles and separation of duties, and audit changes.
Why this matters · English explanation
A reader, analyst and automation identity need different permissions.
Roman Urdu explanation
Har role ko sirf required access do. Reader aur response identity ki permissions alag hoti hain.
Worked context / illustrative example
An analyst investigates while a separate authorised workflow performs sensitive changes.
Your practical task
Build a role-to-task access matrix.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
How would you present an end-to-end Sentinel investigation?
Short interview answer · English
Explain the trigger, evidence, hypothesis testing, scope, response and outcome, including limitations.
Why this matters · English explanation
Separate facts from assumptions and describe what you personally did.
Roman Urdu explanation
Trigger se outcome tak clear story batao. Facts aur assumptions alag rakho, apna actual kaam batao.
Worked context / illustrative example
A lab sign-in incident is investigated, correlated and reported with a justified classification.
Your practical task
Record a two-minute answer and a one-page incident report.
Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.
A cloud SIEM with automation capabilities for detecting, investigating and responding to threats.
2. What is SIEM versus SOAR?
SIEM analyses security events; SOAR orchestrates and automates response workflows.
3. What is a Log Analytics workspace?
A container for Azure Monitor log data and associated configuration.
4. What does a data connector do?
It brings supported security data into Sentinel.
5. What is Content hub?
A place to discover and install Sentinel solutions and standalone content.
6. What is an analytics rule?
Detection logic that evaluates data and can generate alerts.
7. What is an alert versus an incident?
An alert flags a detection; an incident groups related evidence for investigation.
8. What are entities?
Recognised investigation objects such as accounts, hosts and IP addresses.
9. What is KQL used for?
Searching, transforming and aggregating telemetry.
10. How do you choose the correct table?
Match the investigation question to the available telemetry and inspect the schema.
11. What does where do?
It filters rows that satisfy a condition.
12. What does project do?
It selects or calculates output columns.
13. What does summarize do?
It aggregates rows into counts or other statistics.
14. What is extend versus project?
Extend adds calculated columns; project chooses the output columns.
15. How do you find unsuccessful sign-ins?
Filter SigninLogs for a recent period and ResultType not equal to "0".
16. What does bin do?
It groups values into intervals such as five-minute time buckets.
17. What is join versus union?
Join combines rows using matching keys; union stacks compatible result sets.
18. What is parse or extract used for?
Deriving structured fields from text.
19. Why normalise usernames before joining?
Different casing or formats can prevent matches.
20. Why can a KQL query return no results?
Wrong time range, missing data, incorrect table or field, restrictive filters or insufficient access.
21. How do you make a query more efficient?
Reduce time and rows early, select necessary data and avoid unnecessary expensive operations.
22. How do you triage a new incident?
Review severity, affected assets, evidence, timeline and business impact; establish ownership and next actions.
23. How would you investigate suspected brute force?
Review failed and successful sign-ins, targeted accounts, IPs, timing and authentication results.
24. What is password spraying versus brute force?
Spraying tries a few passwords across many accounts; brute force concentrates many guesses on a target.
25. Does impossible travel prove compromise?
No; investigate network routing, VPNs, locations, devices and surrounding events.
26. How do you validate a suspicious IP?
Correlate its activity with account and device evidence, reputation and known business use.
27. How do you investigate a phishing-related incident?
Establish recipients, message identifiers, links, clicks and any subsequent endpoint or identity activity.
28. When would you escalate an incident?
When impact, confidence, scope, required authority or specialist needs exceed my remit.
29. How do you close an incident properly?
Record classification, evidence, actions, remaining risk and the reason for closure.
30. What is a false positive versus benign positive?
A false positive incorrectly detects the intended threat; a benign positive correctly detects behaviour that is legitimate.
31. How do you tune a noisy rule?
Review samples, identify legitimate patterns and adjust scope or logic while testing detection coverage.
32. How do you choose thresholds?
Use baseline behaviour, asset sensitivity, attack patterns and observed false positives.
33. What are query period and frequency?
The period determines how far a scheduled rule looks back; frequency determines how often it runs.
34. What is ingestion latency?
Delay between the event occurring and becoming available for analysis.
35. Why configure entity mapping in a rule?
To associate returned fields with meaningful account, host or IP entities.
36. What is an automation rule?
A condition-based way to manage incidents and trigger supported actions.
37. What is a playbook?
An Azure Logic Apps workflow used to orchestrate response actions.
38. What is automation rule versus playbook?
The rule decides when an action runs; the playbook implements a workflow.
39. How do you troubleshoot a failed playbook?
Check trigger conditions, run history, failed actions, connector authentication and permissions.
40. What is threat hunting?
Proactive investigation of a threat hypothesis using available evidence.
41. What is a hunting bookmark?
A saved investigation finding with relevant query context and evidence.
42. What is a watchlist?
A reference dataset used to enrich or filter investigations and detections.
43. What are workbooks?
Interactive reports for visualising data and investigation context.
44. What is UEBA?
User and entity behaviour analytics that adds behavioural context.
45. How do you use MITRE ATT&CK?
As a vocabulary for attacker tactics and techniques when describing detection coverage.
46. What is ASIM?
Sentinel's Advanced Security Information Model for normalised schemas and parsers.
47. How do you investigate missing logs?
Check source generation, connector status, configuration, permissions, network path, destination table and time range.
48. How do you control Sentinel cost?
Understand ingestion volume, table plans, retention and query patterns; remove unnecessary duplication without losing required evidence.
49. How do you protect access to Sentinel?
Apply least privilege, suitable roles and separation of duties, and audit changes.
50. How would you present an end-to-end Sentinel investigation?
Explain the trigger, evidence, hypothesis testing, scope, response and outcome, including limitations.
Capstone and assessment
Build a lab investigation for repeated sign-in failures followed by suspicious account activity. Submit queries, evidence, alternative explanations, rule-test results and a response recommendation.
Capstone mein evidence, reasoning aur verified result do. Jo cheez available nahin us ki limitation likho. Lab work ko production experience keh kar present mat karo.
Area
Self-assessment target
Evidence and technical accuracy
All key claims supported by relevant records, outputs or diagrams
Investigation reasoning
At least one alternative explanation tested; gaps clearly identified
Practical delivery
Task outcome verified, including one negative or failure test
Communication
Explain the case in two minutes and answer two unprepared follow-ups
This is a study assessment, not a vendor certification or guarantee of interview success. Repeat the task if you cannot explain why your checks were necessary.
Official references and tutorials
References provide deeper detail. Some pages are broad documentation hubs: navigate to the relevant feature and check current licensing, platform support and permissions. Guidance is paraphrased; diagrams and fictional examples are original study material.