Free Microsoft Certified: Security Operations Analyst Associate practice — 6 questions on Manage security threats, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Manage security threats
A threat hunter wants to identify likely command-and-control (C2) beaconing by analyzing outbound connection counts per hour for each device over the last 14 days, looking for a statistically regular, periodic pattern. Which KQL function should be used inside the hunting query to detect this periodicity after building a time series with make-series?
series_decompose_anomalies() analyzes a time series (built with make-series) to detect anomalies and periodic/seasonal patterns, which is the standard KQL approach for surfacing regular beaconing behavior in hunting queries.
Question 2 of 6 · Manage security threats
During an active, still-unfolding incident, an analyst wants to watch for new matching results from a specific hunting query in near real-time as new telemetry arrives in Microsoft Sentinel, without creating a scheduled analytics rule or generating incidents. Which Sentinel feature should the analyst use?
Livestream runs a query continuously against incoming data and surfaces matching results in near real-time on screen, without creating an analytics rule or persisting incidents — ideal for actively monitoring during a live investigation.
Question 3 of 6 · Manage security threats
A company subscribes to a third-party STIX/TAXII threat intelligence feed that pushes updated indicators of compromise (IPs, domains, hashes) every hour. The company wants Microsoft Sentinel to automatically ingest these indicators into the ThreatIntelligenceIndicator table so they can be matched against network and DNS logs. Which data connector should be configured?
The Threat Intelligence - TAXII connector allows Sentinel to connect to any standards-based TAXII 2.x server and automatically pull STIX-formatted indicators on a recurring schedule into the ThreatIntelligenceIndicator table.
Question 4 of 6 · Manage security threats
An organization enables User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel and expects it to baseline normal sign-in patterns and flag anomalous logons from unusual locations for each user. Which prerequisite must be satisfied for UEBA to generate these behavior insights?
UEBA relies on identity and activity source data — primarily SigninLogs and AuditLogs from the Microsoft Entra ID connector — to build entity baselines. UEBA must also be explicitly enabled under Sentinel Settings > Entity behavior before it processes this data into behavior insights and anomaly scores.
Question 5 of 6 · Manage security threats
In Microsoft Sentinel, hunting queries and analytics rules can be tagged with MITRE ATT&CK tactics and techniques. What is the primary benefit of this tagging for a SOC analyst performing proactive threat hunting?
MITRE ATT&CK tagging feeds Sentinel's built-in ATT&CK coverage view/workbook, letting hunters and SOC leads visualize which tactics and techniques already have detection/hunting coverage and prioritize hunting efforts toward uncovered techniques.
Question 6 of 6 · Manage security threats
A hunter runs the following query in Microsoft Defender XDR advanced hunting:
DeviceProcessEvents
| where FileName =~ "powershell.exe"
| project DeviceId, ProcessId, InitiatingProcessCommandLine, TimeGenerated
| join kind=inner (
DeviceNetworkEvents
| project DeviceId, ProcessId = InitiatingProcessId, RemoteIP, RemotePort, TimeGenerated1 = TimeGenerated
) on DeviceId, ProcessId
| where (TimeGenerated1 - TimeGenerated) between (0min .. 5min)
What is this query designed to detect?
The query joins PowerShell process launches to network events by matching DeviceId and ProcessId (as InitiatingProcessId), then filters to connections occurring between 0 and 5 minutes after the process started — surfacing PowerShell instances that quickly reach out over the network, a common indicator of malicious script activity or download-and-execute behavior.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code FREETEST33 — valid through Oct 6.