Guide 01 / 09 • Interview + practical learning

Microsoft Sentinel / KQL

50 representative questions, English and Roman Urdu explanations, examples, exercises and original visual diagrams.

Beginner + intermediate4–6 hours daily50 questions

← Pack index and combined learning plan

How to use this guide

Read the short answer first, then explain the example without reading. Complete the practice task and collect evidence. The 50/40/30/20-question counts follow twice the higher estimates in your table; they are a preparation target, not a guaranteed employer question bank.

Pehle short answer parho, phir example apni zubaan mein samjhao. Practice task complete karke evidence rakho. Answers ratta laganay ke bajaye steps aur reasoning samjho.

Lab requirements: Connected Sentinel workspace or authorised training lab, populated test data, suitable reader/analyst permissions. Automation practice needs supported Logic Apps connectors and permissions. Azure services can incur charges; plan the lab budget and stop unused resources.

Course outcomes / Aap kya kar saken ge

Beginner

  • SIEM, workspace, connector and entity concepts
  • KQL filters, selected columns and counts
  • Simple incident triage and documented classification

SIEM, workspace, connector aur entity concepts samjhao

KQL se filter, columns aur counts banao

Simple incident investigate karke classification document karo

Intermediate

  • Join and aggregate telemetry with justified time windows
  • Design and test a scheduled detection with mapped entities
  • Investigate a multi-source incident and assess false positives
  • Build a basic enrichment workflow and diagnose failures

Tables ko justified timing ke saath join karo

Detection test aur entity mapping verify karo

Multi-source incident aur false positives investigate karo

Basic enrichment workflow aur failure troubleshoot karo

Learning path and practice schedule

This is a suggested 132-hour topic plan: 36 beginner hours plus 96 additional intermediate hours. At 4–6 hours a day, allow approximately 6–9 study days for the beginner stage and 22–33 study days total for this guided course. These are planning estimates, not promises of independent workplace competence. Repeat stages if the practical checkpoints are weak. Related subjects overlap in the combined plan.

Daily routine: 4–6 hours

ActivityCore 4 hoursOptional extra 2 hours
Concepts and official tutorial60 minutes—
Hands-on lab or evidence exercise120 minutes90 minutes: a harder case or failed scenario
Interview answers aloud30 minutes30 minutes: mock interview and follow-ups
Review and evidence log30 minutes—

Roman Urdu: Roz aik ghanta concepts, do ghantay practical, aadha ghanta answers bol kar aur aadha ghanta review karo. Extra do ghantay hon to difficult lab aur mock interview karo. Har haftay chhay study days aur aik rest/catch-up day rakho.

Study time means focused work, excluding breaks. Allocate at least half to practical work. If no tenant or lab is available, analyse supplied data and diagrams, but record that limitation and revisit the task when you have access.

Stage and timeDirection and practiceResource / tutorialDeliverable in Roman Urdu
1. Beginner
12 hours
2–3 study days
Foundations and data flow
Read the overview and configuration path; map two log sources, their destination tables and prerequisites.
Overview and environment path
Configure your Sentinel environment
Do diagrams banao aur prerequisites ki list likho.
2. Beginner
12 hours
2–3 study days
KQL fundamentals
Run ten read-only queries using time filters, where, project and summarize. Explain each output and test an empty result.
KQL tutorial and SigninLogs schema
KQL tutorial
Das queries chalao aur har output ka matlab samjhao.
3. Beginner
12 hours
2–3 study days
Triage basics
Investigate two fictional or lab incidents. Record user, IP, time, evidence, hypotheses and a justified classification.
Detection and investigation path
Create detections and perform investigations
Do incidents ka evidence aur closure note banao.
4. Intermediate
30 hours
5–8 study days
KQL and detection engineering
Practise joins, binning and parsing. Build two lab detections; test known positives, benign activity, delayed data and entity mappings.
Detection path plus KQL reference
Create detections and perform investigations
Do detections test karo aur false positives ka analysis likho.
5. Intermediate
30 hours
5–8 study days
Hunting and automation
Write three hunting hypotheses. Create an enrichment-only workflow; test no-trigger, permission and connector-failure cases.
Hunting and automation references
Automation rules and playbooks
Teen hunts aur aik enrichment workflow ki failure testing karo.
6. Intermediate
36 hours
6–9 study days
Capstone and interview drills
Investigate a simulated sign-in and endpoint scenario, measure scope and produce a report. Revisit missed questions and explain your queries aloud.
Hunting and investigation paths
Perform threat hunting in Sentinel
Complete scenario, report aur mock interview repeat karo.

Practical exit check

Beginner: Complete a basic task using documentation, explain the result and recognise when to escalate.

Intermediate: Complete a common scenario without a step-by-step answer, justify your checks, test an alternative explanation and verify the result. You may consult references as analysts do at work.

Beginner par documentation ke saath basic task karo. Intermediate par ready-made steps ke baghair scenario solve, reasoning explain aur result verify karo.

Visual explanations

Microsoft Sentinel / KQL concept and evidence mapConnected logsKQL + detectionIncident evidenceAnalyst decisionResponse workflow
Original concept diagram. The three inputs on the left contribute to the central investigation or assessment, supporting the decision on the right. Relationships are conceptual, not a screenshot or an exhaustive deployment architecture.

Left ki information central analysis mein use hoti hai, phir decision ya response support hota hai.

Microsoft Sentinel / KQL troubleshooting decision diagramYes / HaanNo / NahinNo query resultsCheck table + timeData present?Simplify queryTrace ingestion
Example troubleshooting decision. Use the branch that matches the observed evidence; complete verification after any corrective action.

Evidence ke mutabiq Yes ya No branch choose karo. Action ke baad result verify karo.

50 interview questions

Level labels indicate study focus, not a formal certification standard. Each short answer is a starting point for a 30–60 second response; expand with the example and your own honest experience.

50 questions shown
  1. What is Microsoft Sentinel?
  2. What is SIEM versus SOAR?
  3. What is a Log Analytics workspace?
  4. What does a data connector do?
  5. What is Content hub?
  6. What is an analytics rule?
  7. What is an alert versus an incident?
  8. What are entities?
  9. What is KQL used for?
  10. How do you choose the correct table?
  11. What does where do?
  12. What does project do?
  13. What does summarize do?
  14. What is extend versus project?
  15. How do you find unsuccessful sign-ins?
  16. What does bin do?
  17. What is join versus union?
  18. What is parse or extract used for?
  19. Why normalise usernames before joining?
  20. Why can a KQL query return no results?
  21. How do you make a query more efficient?
  22. How do you triage a new incident?
  23. How would you investigate suspected brute force?
  24. What is password spraying versus brute force?
  25. Does impossible travel prove compromise?
  26. How do you validate a suspicious IP?
  27. How do you investigate a phishing-related incident?
  28. When would you escalate an incident?
  29. How do you close an incident properly?
  30. What is a false positive versus benign positive?
  31. How do you tune a noisy rule?
  32. How do you choose thresholds?
  33. What are query period and frequency?
  34. What is ingestion latency?
  35. Why configure entity mapping in a rule?
  36. What is an automation rule?
  37. What is a playbook?
  38. What is automation rule versus playbook?
  39. How do you troubleshoot a failed playbook?
  40. What is threat hunting?
  41. What is a hunting bookmark?
  42. What is a watchlist?
  43. What are workbooks?
  44. What is UEBA?
  45. How do you use MITRE ATT&CK?
  46. What is ASIM?
  47. How do you investigate missing logs?
  48. How do you control Sentinel cost?
  49. How do you protect access to Sentinel?
  50. How would you present an end-to-end Sentinel investigation?
Beginner focus
Question 01 / 50

What is Microsoft Sentinel?

Short interview answer · English

A cloud SIEM with automation capabilities for detecting, investigating and responding to threats.

Why this matters · English explanation

It combines security telemetry from different sources so analysts can examine related activity.

Roman Urdu explanation
Sentinel mukhtalif systems ke logs jama karke threat detect aur investigate karne mein madad karta hai.
Worked context / illustrative example
Failed cloud logins and suspicious endpoint activity can be investigated together.
Your practical task
Draw the journey from log source to incident.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Microsoft Sentinel overview

Beginner focus
Question 02 / 50

What is SIEM versus SOAR?

Short interview answer · English

SIEM analyses security events; SOAR orchestrates and automates response workflows.

Why this matters · English explanation

Detection and response are related, but collecting a log does not automatically trigger an action.

Roman Urdu explanation
SIEM logs analyse karta hai; SOAR response ke mukhtalif steps automatically chalata hai.
Worked context / illustrative example
A detection identifies suspicious activity; a playbook enriches the IP and opens a ticket.
Your practical task
Explain one detection and one automated response.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Automation rules and playbooks

Beginner focus
Question 03 / 50

What is a Log Analytics workspace?

Short interview answer · English

A container for Azure Monitor log data and associated configuration.

Why this matters · English explanation

Workspace design affects access, retention, data separation and cost; Sentinel uses workspace-based log analytics for relevant data.

Roman Urdu explanation
Workspace logs aur unki settings ka container hai. Access aur retention bhi plan karni hoti hai.
Worked context / illustrative example
A training workspace receives sign-in logs from a test tenant.
Your practical task
List the data, access and retention needs of a lab.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Configure your Sentinel environment

Beginner focus
Question 04 / 50

What does a data connector do?

Short interview answer · English

It brings supported security data into Sentinel.

Why this matters · English explanation

Connector prerequisites, collection methods and table destinations differ; validate actual records rather than assuming installation means ingestion works.

Roman Urdu explanation
Connector data source ko Sentinel se jorta hai. Install ke baad actual logs check karna zaroori hai.
Worked context / illustrative example
A sign-in connector is configured but permissions prevent collection.
Your practical task
Identify prerequisites for one supported connector.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Connect logs to Sentinel

Beginner focus
Question 05 / 50

What is Content hub?

Short interview answer · English

A place to discover and install Sentinel solutions and standalone content.

Why this matters · English explanation

A solution can include connectors, detection templates, workbooks and playbooks; installation still requires configuration.

Roman Urdu explanation
Content hub mein solutions milti hain. Install karna aur configure karna alag steps hain.
Worked context / illustrative example
Install a solution, then configure its connector and enable a suitable rule.
Your practical task
List the components of one solution.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Configure your Sentinel environment

Beginner focus
Question 06 / 50

What is an analytics rule?

Short interview answer · English

Detection logic that evaluates data and can generate alerts.

Why this matters · English explanation

Scheduled rules use a query, time settings and thresholds; incident creation and entity mapping require suitable configuration.

Roman Urdu explanation
Analytics rule suspicious pattern dhoondti hai. Query, timing aur threshold sahi set karne hote hain.
Worked context / illustrative example
Detect repeated unsuccessful sign-ins within a defined period.
Your practical task
Write the logic and expected false positives first.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Beginner focus
Question 07 / 50

What is an alert versus an incident?

Short interview answer · English

An alert flags a detection; an incident groups related evidence for investigation.

Why this matters · English explanation

One incident can contain multiple alerts, so review the whole attack story rather than one notification.

Roman Urdu explanation
Alert aik detection hai; incident related alerts aur evidence ka investigation case hai.
Worked context / illustrative example
A suspicious login and later privilege change are reviewed in one incident.
Your practical task
Explain why one alert may be insufficient.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Beginner focus
Question 08 / 50

What are entities?

Short interview answer · English

Recognised investigation objects such as accounts, hosts and IP addresses.

Why this matters · English explanation

Entity mapping connects query fields to those objects so analysts can pivot between related evidence.

Roman Urdu explanation
Entities user, device ya IP jaisi cheezen hain jin par investigation pivot karti hai.
Worked context / illustrative example
Map UserPrincipalName to an account entity and IPAddress to an IP entity.
Your practical task
Identify entity fields in a sample query.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Beginner focus
Question 09 / 50

What is KQL used for?

Short interview answer · English

Searching, transforming and aggregating telemetry.

Why this matters · English explanation

KQL log queries read data; their output depends on the selected table, schema, time range and access rights.

Roman Urdu explanation
KQL se logs search, filter aur count karte hain. Table aur time range sahi honi chahiye.
Worked context / illustrative example
Search SigninLogs for one user before counting unsuccessful attempts.
Your practical task
Explain a query one operator at a time.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: KQL tutorial

Beginner focus
Question 10 / 50

How do you choose the correct table?

Short interview answer · English

Match the investigation question to the available telemetry and inspect the schema.

Why this matters · English explanation

Similar-looking events may live in different tables with different field names.

Roman Urdu explanation
Pehle dekho required event kis table mein hai, phir us ke columns check karo.
Worked context / illustrative example
Cloud sign-ins use SigninLogs when that data is connected; host events need other tables.
Your practical task
Inspect five columns in an available table.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: SigninLogs schema and field definitions

Beginner focus
Question 11 / 50

What does where do?

Short interview answer · English

It filters rows that satisfy a condition.

Why this matters · English explanation

Combine a narrow time range with a relevant condition to reduce irrelevant data.

Roman Urdu explanation
Where sirf woh records rakhta hai jo condition poori karte hain.
Worked context / illustrative example
SigninLogs
| where TimeGenerated > ago(1h)
| where UserPrincipalName == "user@example.com"
Your practical task
Change the user and explain both filters.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: KQL tutorial

Beginner focus
Question 12 / 50

What does project do?

Short interview answer · English

It selects or calculates output columns.

Why this matters · English explanation

Use it to produce readable evidence without exporting unnecessary fields.

Roman Urdu explanation
Project required columns dikhata hai taake result samajhna aasaan ho.
Worked context / illustrative example
SigninLogs
| project TimeGenerated, UserPrincipalName, IPAddress, ResultType
Your practical task
Explain why these fields help sign-in triage.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: SigninLogs schema and field definitions

Beginner focus
Question 13 / 50

What does summarize do?

Short interview answer · English

It aggregates rows into counts or other statistics.

Why this matters · English explanation

Grouping determines what each result represents; counting by user differs from counting by user and IP.

Roman Urdu explanation
Summarize logs ka count ya summary banata hai. Grouping badlay to result ka matlab bhi badalta hai.
Worked context / illustrative example
SigninLogs
| summarize Attempts=count() by UserPrincipalName
Your practical task
Compare a per-user count with a per-IP count.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: KQL tutorial

Beginner focus
Question 14 / 50

What is extend versus project?

Short interview answer · English

Extend adds calculated columns; project chooses the output columns.

Why this matters · English explanation

Keeping the original fields can help explain how a derived value was calculated.

Roman Urdu explanation
Extend naya calculated column add karta hai; project output columns select karta hai.
Worked context / illustrative example
SigninLogs
| extend Successful = ResultType == "0"
| project UserPrincipalName, Successful
Your practical task
Create a calculated column and retain its input.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: SigninLogs schema and field definitions

Beginner focus
Question 15 / 50

How do you find unsuccessful sign-ins?

Short interview answer · English

Filter SigninLogs for a recent period and ResultType not equal to "0".

Why this matters · English explanation

These are unsuccessful events, not automatic proof of password attacks.

Roman Urdu explanation
ResultType zero ke ilawa unsuccessful sign-in hai. Har failure attack nahin hota.
Worked context / illustrative example
SigninLogs
| where TimeGenerated > ago(24h)
| where ResultType != "0"
| summarize Attempts=count() by UserPrincipalName, IPAddress
Your practical task
Add a threshold and explain its limitations.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: SigninLogs schema and field definitions

Beginner focus
Question 16 / 50

What does bin do?

Short interview answer · English

It groups values into intervals such as five-minute time buckets.

Why this matters · English explanation

Fixed buckets are not sliding windows and can split a burst across boundaries.

Roman Urdu explanation
Bin time ko chotay intervals mein group karta hai. Boundary par aik burst do groups mein aa sakta hai.
Worked context / illustrative example
SigninLogs
| summarize Attempts=count() by bin(TimeGenerated, 5m), IPAddress
Your practical task
Explain how bucket boundaries affect detection.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: KQL tutorial

Beginner focus
Question 17 / 50

What is join versus union?

Short interview answer · English

Join combines rows using matching keys; union stacks compatible result sets.

Why this matters · English explanation

Choose a join type carefully and watch for duplicated rows or missing matches.

Roman Urdu explanation
Join matching key par tables jorta hai; union records aik result mein jama karta hai.
Worked context / illustrative example
Join an account event with another table using a consistently normalised user identifier.
Your practical task
Sketch leftouter and inner results using three sample rows.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: KQL tutorial

Beginner focus
Question 18 / 50

What is parse or extract used for?

Short interview answer · English

Deriving structured fields from text.

Why this matters · English explanation

Prefer existing structured columns; test missing fields and unexpected formats when parsing is necessary.

Roman Urdu explanation
Text ke andar se field nikalne ke liye parse ya extract use hota hai.
Worked context / illustrative example
Extract an account value from a fictional custom log message.
Your practical task
Test a matching, nonmatching and empty message.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: KQL tutorial

Beginner focus
Question 19 / 50

Why normalise usernames before joining?

Short interview answer · English

Different casing or formats can prevent matches.

Why this matters · English explanation

Use consistent identifiers and understand that display names are not always unique.

Roman Urdu explanation
Username ka case ya format different ho to join miss ho sakta hai. Unique identifier behtar hota hai.
Worked context / illustrative example
user@example.com and USER@example.com need consistent treatment in a matching operation.
Your practical task
Describe a collision caused by using display names.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: KQL tutorial

Beginner focus
Question 20 / 50

Why can a KQL query return no results?

Short interview answer · English

Wrong time range, missing data, incorrect table or field, restrictive filters or insufficient access.

Why this matters · English explanation

Test a small base query, then add filters one at a time.

Roman Urdu explanation
No result par time range, table, data aur permissions check karo. Filters aik aik karke lagao.
Worked context / illustrative example
A query uses the last hour, but the sample data is from yesterday.
Your practical task
Write a five-step no-results checklist.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Connect logs to Sentinel

Beginner focus
Question 21 / 50

How do you make a query more efficient?

Short interview answer · English

Reduce time and rows early, select necessary data and avoid unnecessary expensive operations.

Why this matters · English explanation

Measure performance rather than assuming a shorter query is always faster.

Roman Urdu explanation
Pehle relevant time aur records filter karo. Query ki performance measure bhi karo.
Worked context / illustrative example
Filter before a large join and select only required columns.
Your practical task
Compare two logically equivalent lab queries.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: KQL tutorial

Beginner focus
Question 22 / 50

How do you triage a new incident?

Short interview answer · English

Review severity, affected assets, evidence, timeline and business impact; establish ownership and next actions.

Why this matters · English explanation

Severity helps prioritisation, but a critical asset can change operational urgency.

Roman Urdu explanation
Severity ke saath affected asset aur business impact bhi dekho. Owner aur next action clear karo.
Worked context / illustrative example
A medium alert on a critical server may need urgent review.
Your practical task
Write a triage note with facts and open questions.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Intermediate focus
Question 23 / 50

How would you investigate suspected brute force?

Short interview answer · English

Review failed and successful sign-ins, targeted accounts, IPs, timing and authentication results.

Why this matters · English explanation

Distinguish malicious attempts from user mistakes or applications with outdated credentials.

Roman Urdu explanation
Failures, successful login, users aur IPs compare karo. Old password wali application bhi failures bana sakti hai.
Worked context / illustrative example
Twenty failures followed by a successful login require further verification.
Your practical task
Explain three legitimate and three suspicious indicators.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: SigninLogs schema and field definitions

Beginner focus
Question 24 / 50

What is password spraying versus brute force?

Short interview answer · English

Spraying tries a few passwords across many accounts; brute force concentrates many guesses on a target.

Why this matters · English explanation

Detection grouping should match the behaviour, not just count all failures together.

Roman Urdu explanation
Spraying bohat users par chand passwords try karta hai; brute force aik target par bohat guesses karta hai.
Worked context / illustrative example
One IP targets fifty users with two attempts each.
Your practical task
Design a lab query counting distinct targeted users.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Beginner focus
Question 25 / 50

Does impossible travel prove compromise?

Short interview answer · English

No; investigate network routing, VPNs, locations, devices and surrounding events.

Why this matters · English explanation

Geolocation is a clue, not a reliable record of a person's physical location.

Roman Urdu explanation
Impossible travel clue hai, final proof nahin. VPN aur location accuracy bhi check karo.
Worked context / illustrative example
A company VPN makes a UK employee appear abroad.
Your practical task
List evidence that would strengthen the compromise hypothesis.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Intermediate focus
Question 26 / 50

How do you validate a suspicious IP?

Short interview answer · English

Correlate its activity with account and device evidence, reputation and known business use.

Why this matters · English explanation

An IP reputation result alone does not establish compromise; shared addresses can affect attribution.

Roman Urdu explanation
IP reputation ke saath actual activity aur business use check karo. Shared IP ki attribution mushkil hoti hai.
Worked context / illustrative example
An unfamiliar IP belongs to an approved remote access service.
Your practical task
Document supporting and conflicting evidence.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Perform threat hunting in Sentinel

Intermediate focus
Question 27 / 50

How do you investigate a phishing-related incident?

Short interview answer · English

Establish recipients, message identifiers, links, clicks and any subsequent endpoint or identity activity.

Why this matters · English explanation

Use appropriate connected telemetry and coordinate email response with the authorised team.

Roman Urdu explanation
Recipients, link clicks aur baad ki device ya login activity joro. Email team se coordinate karo.
Worked context / illustrative example
A click is followed by a suspicious login for the same user.
Your practical task
Build a fictional timeline with three evidence sources.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Intermediate focus
Question 28 / 50

When would you escalate an incident?

Short interview answer · English

When impact, confidence, scope, required authority or specialist needs exceed my remit.

Why this matters · English explanation

Provide evidence, actions already taken, affected assets and a clear request.

Roman Urdu explanation
Jab impact ya required action meri authority se bahar ho to evidence ke saath escalate karunga.
Worked context / illustrative example
Suspected compromise of a privileged account requires urgent escalation.
Your practical task
Write a concise escalation message without claiming certainty.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Intermediate focus
Question 29 / 50

How do you close an incident properly?

Short interview answer · English

Record classification, evidence, actions, remaining risk and the reason for closure.

Why this matters · English explanation

Use the organisation's classification definitions and avoid closing unresolved questions without ownership.

Roman Urdu explanation
Closure mein evidence, action aur reason likho. Pending risk ka owner bhi clear hona chahiye.
Worked context / illustrative example
A legitimate administrator activity is verified and documented before closure.
Your practical task
Write a closure note for a benign activity scenario.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Intermediate focus
Question 30 / 50

What is a false positive versus benign positive?

Short interview answer · English

A false positive incorrectly detects the intended threat; a benign positive correctly detects behaviour that is legitimate.

Why this matters · English explanation

Use the organisation's classification scheme consistently.

Roman Urdu explanation
False positive mein detection ghalat hoti hai; benign positive mein activity detect sahi hui magar legitimate thi.
Worked context / illustrative example
An authorised simulation triggers a real suspicious-behaviour rule.
Your practical task
Explain the distinction without relying only on alert severity.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Intermediate focus
Question 31 / 50

How do you tune a noisy rule?

Short interview answer · English

Review samples, identify legitimate patterns and adjust scope or logic while testing detection coverage.

Why this matters · English explanation

Broad exclusions reduce noise but can hide attacks; document why each exception exists.

Roman Urdu explanation
Noise ki wajah samjho, phir limited tuning karo. Bara exclusion attack chhupa sakta hai.
Worked context / illustrative example
Exclude a validated service pattern rather than every event from an entire subnet.
Your practical task
Compare detections before and after one lab change.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Intermediate focus
Question 32 / 50

How do you choose thresholds?

Short interview answer · English

Use baseline behaviour, asset sensitivity, attack patterns and observed false positives.

Why this matters · English explanation

Thresholds are environment-specific; a number from a tutorial is only a starting point.

Roman Urdu explanation
Threshold normal activity aur risk dekh kar set hota hai. Tutorial ka number final standard nahin.
Worked context / illustrative example
Ten failures in a day may be common; a burst against an admin account is more concerning.
Your practical task
Propose a threshold and explain the trade-off.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Intermediate focus
Question 33 / 50

What are query period and frequency?

Short interview answer · English

The period determines how far a scheduled rule looks back; frequency determines how often it runs.

Why this matters · English explanation

Overlapping periods and ingestion delays influence duplicates and missed events.

Roman Urdu explanation
Period pichlay kitnay logs dekhta hai; frequency rule kitni dair baad chalti hai.
Worked context / illustrative example
A rule runs every five minutes and searches a longer lookback window.
Your practical task
Draw two overlapping evaluation windows.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Intermediate focus
Question 34 / 50

What is ingestion latency?

Short interview answer · English

Delay between the event occurring and becoming available for analysis.

Why this matters · English explanation

Differentiate event time from ingestion time and account for late arrival in detection design.

Roman Urdu explanation
Event aur log available honay ke darmiyan delay ingestion latency hai.
Worked context / illustrative example
A delayed network log arrives after the shortest rule window has passed.
Your practical task
Explain how to diagnose late data without changing event timestamps.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Connect logs to Sentinel

Intermediate focus
Question 35 / 50

Why configure entity mapping in a rule?

Short interview answer · English

To associate returned fields with meaningful account, host or IP entities.

Why this matters · English explanation

Correct mappings support investigation pivots; wrong identifiers can produce misleading relationships.

Roman Urdu explanation
Sahi entity mapping related user, host aur IP par pivot mein madad karti hai.
Worked context / illustrative example
Map a real account identifier rather than a nonunique display name.
Your practical task
Check mappings against three query result rows.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Intermediate focus
Question 36 / 50

What is an automation rule?

Short interview answer · English

A condition-based way to manage incidents and trigger supported actions.

Why this matters · English explanation

It can assign, tag or invoke playbooks depending on configuration; order and conditions matter.

Roman Urdu explanation
Automation rule condition par incident assign, tag ya playbook trigger kar sakti hai.
Worked context / illustrative example
Tag an incident category and route it to a suitable team.
Your practical task
Design one rule without destructive response actions.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Automation rules and playbooks

Intermediate focus
Question 37 / 50

What is a playbook?

Short interview answer · English

An Azure Logic Apps workflow used to orchestrate response actions.

Why this matters · English explanation

Its connectors, identity, permissions and error handling determine what it can safely do.

Roman Urdu explanation
Playbook Logic Apps workflow hai. Permissions aur failed steps ka handling zaroori hai.
Worked context / illustrative example
Look up an IP, add context to an incident and notify a test mailbox.
Your practical task
Sketch the workflow and a failed-lookup branch.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Automation rules and playbooks

Intermediate focus
Question 38 / 50

What is automation rule versus playbook?

Short interview answer · English

The rule decides when an action runs; the playbook implements a workflow.

Why this matters · English explanation

Simple incident-management actions may not require a separate playbook.

Roman Urdu explanation
Rule batati hai kab action ho; playbook batata hai workflow mein kya steps hon.
Worked context / illustrative example
A high-priority incident condition triggers an enrichment workflow.
Your practical task
Explain why assigning an owner may need only a rule.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Automation rules and playbooks

Intermediate focus
Question 39 / 50

How do you troubleshoot a failed playbook?

Short interview answer · English

Check trigger conditions, run history, failed actions, connector authentication and permissions.

Why this matters · English explanation

Separate a workflow that never started from one that started and failed midway.

Roman Urdu explanation
Pehle dekho trigger chala ya nahin; phir run history, credentials aur permissions check karo.
Worked context / illustrative example
A workflow starts but its incident update action receives access denied.
Your practical task
Write separate checklists for no trigger and failed action.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Automation rules and playbooks

Intermediate focus
Question 40 / 50

What is threat hunting?

Short interview answer · English

Proactive investigation of a threat hypothesis using available evidence.

Why this matters · English explanation

Hunting is not limited to alerts; record the hypothesis, data coverage, findings and limitations.

Roman Urdu explanation
Hunting mein hypothesis bana kar logs mein evidence dhoondte hain, sirf alerts ka wait nahin karte.
Worked context / illustrative example
Hunt for unusual administrative sign-ins outside the established baseline.
Your practical task
Write one hypothesis and an alternative explanation.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Perform threat hunting in Sentinel

Intermediate focus
Question 41 / 50

What is a hunting bookmark?

Short interview answer · English

A saved investigation finding with relevant query context and evidence.

Why this matters · English explanation

Useful notes explain why the result matters and how another analyst can reproduce it.

Roman Urdu explanation
Bookmark important finding aur query context save karta hai. Reason likhna bhi zaroori hai.
Worked context / illustrative example
Save a suspicious account-event result with the time range and investigation note.
Your practical task
Draft a reproducible bookmark description.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Perform threat hunting in Sentinel

Intermediate focus
Question 42 / 50

What is a watchlist?

Short interview answer · English

A reference dataset used to enrich or filter investigations and detections.

Why this matters · English explanation

Ownership, freshness and matching keys matter; stale exceptions can create blind spots.

Roman Urdu explanation
Watchlist reference data hai. Owner, latest update aur matching key sahi honi chahiye.
Worked context / illustrative example
Compare observed accounts with a maintained list of privileged accounts.
Your practical task
Create a fictional list and define its review schedule.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Configure your Sentinel environment

Intermediate focus
Question 43 / 50

What are workbooks?

Short interview answer · English

Interactive reports for visualising data and investigation context.

Why this matters · English explanation

A visualisation summarises queries; it does not replace detailed evidence or create a detection by itself.

Roman Urdu explanation
Workbook dashboard aur reports dikhata hai. Dashboard khud detection rule nahin hai.
Worked context / illustrative example
Show failed sign-ins by time and user for operational review.
Your practical task
Define three useful metrics and their limitations.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Configure your Sentinel environment

Intermediate focus
Question 44 / 50

What is UEBA?

Short interview answer · English

User and entity behaviour analytics that adds behavioural context.

Why this matters · English explanation

Anomalies need investigation because unusual behaviour can also be legitimate.

Roman Urdu explanation
UEBA user aur entity ke unusual behaviour ka context deta hai. Unusual ka matlab hamesha malicious nahin.
Worked context / illustrative example
An administrator changes working hours during an approved maintenance window.
Your practical task
List context needed before treating an anomaly as malicious.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Intermediate focus
Question 45 / 50

How do you use MITRE ATT&CK?

Short interview answer · English

As a vocabulary for attacker tactics and techniques when describing detection coverage.

Why this matters · English explanation

A technique mapping explains behaviour; it does not prove that an entire attack chain is covered.

Roman Urdu explanation
MITRE ATT&CK attack behaviour ko classify karne mein madad deta hai. Mapping full coverage ki guarantee nahin.
Worked context / illustrative example
Describe credential guessing separately from later lateral movement.
Your practical task
Map a scenario to behaviour and identify missing telemetry.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Perform threat hunting in Sentinel

Intermediate focus
Question 46 / 50

What is ASIM?

Short interview answer · English

Sentinel's Advanced Security Information Model for normalised schemas and parsers.

Why this matters · English explanation

Normalisation helps queries work across sources, but requires relevant parsers and source coverage.

Roman Urdu explanation
ASIM different sources ko common schema mein laata hai. Parser aur data coverage check karo.
Worked context / illustrative example
Query normalised authentication events instead of maintaining separate source-specific logic.
Your practical task
Explain why normalisation helps multi-vendor investigations.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Intermediate focus
Question 47 / 50

How do you investigate missing logs?

Short interview answer · English

Check source generation, connector status, configuration, permissions, network path, destination table and time range.

Why this matters · English explanation

Identify the first broken stage instead of repeatedly rewriting the detection query.

Roman Urdu explanation
Source se workspace tak har stage check karo taake missing logs ki asal wajah milay.
Worked context / illustrative example
The source sends events, but the ingestion configuration points to another workspace.
Your practical task
Draw a troubleshooting checklist from source to query.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Connect logs to Sentinel

Intermediate focus
Question 48 / 50

How do you control Sentinel cost?

Short interview answer · English

Understand ingestion volume, table plans, retention and query patterns; remove unnecessary duplication without losing required evidence.

Why this matters · English explanation

Set a budget and measure before changing collection scope.

Roman Urdu explanation
Data volume, retention aur duplicate collection check karo. Cost kam karte waqt required evidence na kho do.
Worked context / illustrative example
Verbose low-value logs dominate ingestion while essential authentication data is small.
Your practical task
Produce a lab cost checklist rather than a price promise.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Configure your Sentinel environment

Intermediate focus
Question 49 / 50

How do you protect access to Sentinel?

Short interview answer · English

Apply least privilege, suitable roles and separation of duties, and audit changes.

Why this matters · English explanation

A reader, analyst and automation identity need different permissions.

Roman Urdu explanation
Har role ko sirf required access do. Reader aur response identity ki permissions alag hoti hain.
Worked context / illustrative example
An analyst investigates while a separate authorised workflow performs sensitive changes.
Your practical task
Build a role-to-task access matrix.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Configure your Sentinel environment

Intermediate focus
Question 50 / 50

How would you present an end-to-end Sentinel investigation?

Short interview answer · English

Explain the trigger, evidence, hypothesis testing, scope, response and outcome, including limitations.

Why this matters · English explanation

Separate facts from assumptions and describe what you personally did.

Roman Urdu explanation
Trigger se outcome tak clear story batao. Facts aur assumptions alag rakho, apna actual kaam batao.
Worked context / illustrative example
A lab sign-in incident is investigated, correlated and reported with a justified classification.
Your practical task
Record a two-minute answer and a one-page incident report.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Create detections and perform investigations

Quick revision sheet

Cover the answers and explain each question aloud. For scenarios use: Trigger → Evidence → Checks → Decision → Verification → Documentation.

Scenario answer mein trigger, evidence, checks, decision, verification aur documentation clear batao.

QuestionAnswer prompt
1. What is Microsoft Sentinel?A cloud SIEM with automation capabilities for detecting, investigating and responding to threats.
2. What is SIEM versus SOAR?SIEM analyses security events; SOAR orchestrates and automates response workflows.
3. What is a Log Analytics workspace?A container for Azure Monitor log data and associated configuration.
4. What does a data connector do?It brings supported security data into Sentinel.
5. What is Content hub?A place to discover and install Sentinel solutions and standalone content.
6. What is an analytics rule?Detection logic that evaluates data and can generate alerts.
7. What is an alert versus an incident?An alert flags a detection; an incident groups related evidence for investigation.
8. What are entities?Recognised investigation objects such as accounts, hosts and IP addresses.
9. What is KQL used for?Searching, transforming and aggregating telemetry.
10. How do you choose the correct table?Match the investigation question to the available telemetry and inspect the schema.
11. What does where do?It filters rows that satisfy a condition.
12. What does project do?It selects or calculates output columns.
13. What does summarize do?It aggregates rows into counts or other statistics.
14. What is extend versus project?Extend adds calculated columns; project chooses the output columns.
15. How do you find unsuccessful sign-ins?Filter SigninLogs for a recent period and ResultType not equal to "0".
16. What does bin do?It groups values into intervals such as five-minute time buckets.
17. What is join versus union?Join combines rows using matching keys; union stacks compatible result sets.
18. What is parse or extract used for?Deriving structured fields from text.
19. Why normalise usernames before joining?Different casing or formats can prevent matches.
20. Why can a KQL query return no results?Wrong time range, missing data, incorrect table or field, restrictive filters or insufficient access.
21. How do you make a query more efficient?Reduce time and rows early, select necessary data and avoid unnecessary expensive operations.
22. How do you triage a new incident?Review severity, affected assets, evidence, timeline and business impact; establish ownership and next actions.
23. How would you investigate suspected brute force?Review failed and successful sign-ins, targeted accounts, IPs, timing and authentication results.
24. What is password spraying versus brute force?Spraying tries a few passwords across many accounts; brute force concentrates many guesses on a target.
25. Does impossible travel prove compromise?No; investigate network routing, VPNs, locations, devices and surrounding events.
26. How do you validate a suspicious IP?Correlate its activity with account and device evidence, reputation and known business use.
27. How do you investigate a phishing-related incident?Establish recipients, message identifiers, links, clicks and any subsequent endpoint or identity activity.
28. When would you escalate an incident?When impact, confidence, scope, required authority or specialist needs exceed my remit.
29. How do you close an incident properly?Record classification, evidence, actions, remaining risk and the reason for closure.
30. What is a false positive versus benign positive?A false positive incorrectly detects the intended threat; a benign positive correctly detects behaviour that is legitimate.
31. How do you tune a noisy rule?Review samples, identify legitimate patterns and adjust scope or logic while testing detection coverage.
32. How do you choose thresholds?Use baseline behaviour, asset sensitivity, attack patterns and observed false positives.
33. What are query period and frequency?The period determines how far a scheduled rule looks back; frequency determines how often it runs.
34. What is ingestion latency?Delay between the event occurring and becoming available for analysis.
35. Why configure entity mapping in a rule?To associate returned fields with meaningful account, host or IP entities.
36. What is an automation rule?A condition-based way to manage incidents and trigger supported actions.
37. What is a playbook?An Azure Logic Apps workflow used to orchestrate response actions.
38. What is automation rule versus playbook?The rule decides when an action runs; the playbook implements a workflow.
39. How do you troubleshoot a failed playbook?Check trigger conditions, run history, failed actions, connector authentication and permissions.
40. What is threat hunting?Proactive investigation of a threat hypothesis using available evidence.
41. What is a hunting bookmark?A saved investigation finding with relevant query context and evidence.
42. What is a watchlist?A reference dataset used to enrich or filter investigations and detections.
43. What are workbooks?Interactive reports for visualising data and investigation context.
44. What is UEBA?User and entity behaviour analytics that adds behavioural context.
45. How do you use MITRE ATT&CK?As a vocabulary for attacker tactics and techniques when describing detection coverage.
46. What is ASIM?Sentinel's Advanced Security Information Model for normalised schemas and parsers.
47. How do you investigate missing logs?Check source generation, connector status, configuration, permissions, network path, destination table and time range.
48. How do you control Sentinel cost?Understand ingestion volume, table plans, retention and query patterns; remove unnecessary duplication without losing required evidence.
49. How do you protect access to Sentinel?Apply least privilege, suitable roles and separation of duties, and audit changes.
50. How would you present an end-to-end Sentinel investigation?Explain the trigger, evidence, hypothesis testing, scope, response and outcome, including limitations.

Capstone and assessment

Build a lab investigation for repeated sign-in failures followed by suspicious account activity. Submit queries, evidence, alternative explanations, rule-test results and a response recommendation.

Capstone mein evidence, reasoning aur verified result do. Jo cheez available nahin us ki limitation likho. Lab work ko production experience keh kar present mat karo.

AreaSelf-assessment target
Evidence and technical accuracyAll key claims supported by relevant records, outputs or diagrams
Investigation reasoningAt least one alternative explanation tested; gaps clearly identified
Practical deliveryTask outcome verified, including one negative or failure test
CommunicationExplain the case in two minutes and answer two unprepared follow-ups

This is a study assessment, not a vendor certification or guarantee of interview success. Repeat the task if you cannot explain why your checks were necessary.

Official references and tutorials

References provide deeper detail. Some pages are broad documentation hubs: navigate to the relevant feature and check current licensing, platform support and permissions. Guidance is paraphrased; diagrams and fictional examples are original study material.