certslothcertsloth
SC-200/Topic 06

Microsoft / Associate

KQL Hunting and Evidence Quality

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Filter early, preserve identifiers, test the hypothesis.

Must remember

Choose the table whose schema represents the activity: device processes, network connections, sign-ins and email events are different evidence. Inspect sample rows and available columns before writing joins. Limit time and project needed fields early to control cost and result volume.

where filters, project selects/computes columns, extend adds columns and summarize aggregates. bin groups values into intervals. has uses term semantics while contains searches substrings; case-sensitive variants and exact comparisons can matter for correctness and speed. Parse structured dynamic fields deliberately and validate null/type behavior.

Join on stable keys and appropriate time relationships. A many-to-many join can multiply evidence and create misleading counts. Use distinct identifiers or an explicit deduplication strategy where justified, preserving the raw evidence for review. Union combines compatible results; it does not correlate them by identity.

A hunt starts with a falsifiable hypothesis, relevant telemetry and an expected pattern. Record the query, time range, evidence and confidence. A result is a lead; absence can mean no activity, missing data or an inadequate query. Save useful queries, monitor them and promote repeatable high-value logic into detections after testing.

Use Defender threat analytics for context about campaigns and mitigations, then check applicability to your environment. Advanced hunting queries and Sentinel queries may use different schemas despite both being KQL. Preserve required fields when converting a hunt to a custom detection; a summarized chart may omit identifiers needed for an actionable alert.

Choose under exam pressure

Requirement Choice and reason
Find a whole command-line term Consider has with the intended token semantics.
Correlate account activity across sources Join validated stable identifiers and time windows.
Repeated useful hunt should alert automatically Test and convert it into an appropriate detection rule.

Traps

  • No query results cannot prove absence when collection is incomplete.
  • Aggregating away entity IDs can make a detection unusable.

Active recall

1. project versus extend?

Select/compute output columns versus add calculated columns while retaining existing ones.

2. has versus contains?

Term matching versus substring matching.

3. Why inspect join cardinality?

To avoid multiplied rows and false activity counts.

4. What makes a useful hunting hypothesis?

A specific testable claim linked to available evidence.

5. Why not paste queries blindly between products?

Schemas, available tables and detection requirements differ.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.