Bird
Raised Fist0
Azurecloud~10 mins

Azure Sentinel for SIEM - Interactive Code Practice

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Practice - 5 Tasks
Answer the questions below
1fill in blank
easy

Complete the code to create an Azure Sentinel workspace in Azure.

Azure
az monitor log-analytics workspace create --resource-group myResourceGroup --workspace-name [1] --location eastus
Drag options to blanks, or click blank then click option'
AMyAppService
BMyStorageAccount
CMyVirtualNetwork
DMySentinelWorkspace
Attempts:
3 left
💡 Hint
Common Mistakes
Using a storage account name instead of a workspace name.
Using a virtual network name instead of a workspace name.
2fill in blank
medium

Complete the code to enable data connectors for Azure Sentinel.

Azure
az sentinel data-connector [1] create --resource-group myResourceGroup --workspace-name myWorkspace
Drag options to blanks, or click blank then click option'
AVirtualMachines
BSecurityEvents
CStorageAccounts
DAppServices
Attempts:
3 left
💡 Hint
Common Mistakes
Choosing VirtualMachines or StorageAccounts which are not data connector types.
Using AppServices which is unrelated to Sentinel data connectors.
3fill in blank
hard

Fix the error in the Kusto query to find failed sign-in attempts in Azure Sentinel logs.

Azure
SigninLogs | where ResultType [1] 0
Drag options to blanks, or click blank then click option'
A!=
B==
C>
D<
Attempts:
3 left
💡 Hint
Common Mistakes
Using '==' which filters only successful sign-ins.
Using '>' or '<' which may not correctly filter failures.
4fill in blank
hard

Fill both blanks to create an alert rule that triggers on multiple failed sign-ins.

Azure
SigninLogs | where ResultType [1] 0 | summarize count() by UserPrincipalName | where count_ [2] 5
Drag options to blanks, or click blank then click option'
A!=
B>
C<
D==
Attempts:
3 left
💡 Hint
Common Mistakes
Using '==' instead of '!=' for ResultType.
Using '<' or '==' instead of '>' for count.
5fill in blank
hard

Fill all three blanks to create a playbook trigger for an Azure Sentinel alert.

Azure
az sentinel alert-rule analytics create --resource-group myResourceGroup --workspace-name myWorkspace --display-name [1] --severity [2] --enabled [3]
Drag options to blanks, or click blank then click option'
AHighAlert
BHigh
Ctrue
DLow
Efalse
FMedium
GCritical
Attempts:
3 left
💡 Hint
Common Mistakes
Using false for enabled disables the alert.
Choosing Low or Medium severity when High is required.

Practice

(1/5)
1. What is the main purpose of Azure Sentinel in security management?
easy
A. To provide cloud storage for application data
B. To collect and analyze security data for threat detection
C. To manage user passwords and authentication
D. To store backups of all user files

Solution

  1. Step 1: Understand Azure Sentinel's role

    Azure Sentinel is designed to collect security data from various sources to detect threats.
  2. Step 2: Compare options with Sentinel's function

    Only To collect and analyze security data for threat detection describes collecting and analyzing security data for threat detection, which matches Sentinel's purpose.
  3. Final Answer:

    To collect and analyze security data for threat detection -> Option B
  4. Quick Check:

    Azure Sentinel = threat detection [OK]
Hint: Remember: Sentinel = security data + threat detection [OK]
Common Mistakes:
  • Confusing Sentinel with backup or storage services
  • Thinking Sentinel manages passwords directly
  • Assuming Sentinel is just cloud storage
2. Which of the following is the correct way to create an alert rule query in Azure Sentinel using Kusto Query Language (KQL)?
easy
A. GET SecurityEvent WHERE EventID = 4625
B. SELECT * FROM SecurityEvent WHERE EventID = 4625
C. FIND SecurityEvent WITH EventID 4625
D. SecurityEvent | where EventID == 4625

Solution

  1. Step 1: Identify the query language used in Azure Sentinel

    Azure Sentinel uses Kusto Query Language (KQL), which uses pipe operators and 'where' clauses.
  2. Step 2: Match the syntax to KQL

    SecurityEvent | where EventID == 4625 uses KQL syntax correctly: table name, pipe, and 'where' condition. Other options use SQL or invalid syntax.
  3. Final Answer:

    SecurityEvent | where EventID == 4625 -> Option D
  4. Quick Check:

    KQL uses pipes and 'where' [OK]
Hint: KQL uses pipes (|) and 'where' for filters [OK]
Common Mistakes:
  • Using SQL syntax instead of KQL
  • Missing pipe operator in query
  • Using incorrect keywords like GET or FIND
3. Given the following KQL query in Azure Sentinel alert rule:
SecurityEvent | where EventID == 4625 | summarize count() by Account
What does this query output?
medium
A. A count of all events without grouping
B. A list of all successful login events
C. A count of failed login attempts grouped by user account
D. A list of accounts with no login attempts

Solution

  1. Step 1: Analyze the query filters and aggregation

    The query filters SecurityEvent for EventID 4625, which means failed login attempts, then counts them grouped by Account.
  2. Step 2: Understand the summarize clause

    'summarize count() by Account' groups results by Account and counts events per account.
  3. Final Answer:

    A count of failed login attempts grouped by user account -> Option C
  4. Quick Check:

    EventID 4625 = failed logins, grouped count = A count of failed login attempts grouped by user account [OK]
Hint: EventID 4625 means failed login; summarize groups counts [OK]
Common Mistakes:
  • Confusing EventID 4625 with successful logins
  • Ignoring the grouping by Account
  • Thinking it lists accounts without attempts
4. You wrote this KQL alert rule query in Azure Sentinel:
SecurityEvent | where EventID = 4625 | summarize count() by Account
Why does this query fail to run correctly?
medium
A. Because the equality operator should be '==' not '=' in KQL
B. Because 'summarize' cannot be used with 'count()'
C. Because 'Account' is not a valid field in SecurityEvent
D. Because 'where' clause must come after 'summarize'

Solution

  1. Step 1: Check the operator syntax in the 'where' clause

    KQL requires '==' for equality comparison, not a single '=' which is assignment in some languages.
  2. Step 2: Validate other parts of the query

    'summarize count() by Account' is valid, and 'Account' is a common field. 'where' must come before 'summarize'.
  3. Final Answer:

    Because the equality operator should be '==' not '=' in KQL -> Option A
  4. Quick Check:

    KQL equality uses '==' not '=' [OK]
Hint: Use '==' for equality in KQL, not '=' [OK]
Common Mistakes:
  • Using single '=' instead of '==' in KQL
  • Misplacing 'where' after 'summarize'
  • Assuming 'count()' is invalid with 'summarize'
5. You want to create an Azure Sentinel alert that triggers when there are more than 5 failed login attempts from the same account within 10 minutes. Which KQL query correctly implements this logic?
hard
A. SecurityEvent | where EventID == 4625 | where TimeGenerated > ago(10m) | summarize FailedAttempts = count() by Account | where FailedAttempts > 5
B. SecurityEvent | where EventID == 4625 | summarize count() by Account | where count_ > 5
C. SecurityEvent | where EventID == 4625 and TimeGenerated < ago(10m) | summarize count() by Account | where count_ > 5
D. SecurityEvent | where EventID == 4625 | summarize count() by Account, TimeGenerated | where count_ > 5

Solution

  1. Step 1: Filter failed login events within last 10 minutes

    SecurityEvent | where EventID == 4625 | where TimeGenerated > ago(10m) | summarize FailedAttempts = count() by Account | where FailedAttempts > 5 uses 'where TimeGenerated > ago(10m)' to filter recent events correctly.
  2. Step 2: Group by Account and count attempts, then filter counts over 5

    SecurityEvent | where EventID == 4625 | where TimeGenerated > ago(10m) | summarize FailedAttempts = count() by Account | where FailedAttempts > 5 summarizes counts by Account and filters where count > 5, matching the requirement.
  3. Final Answer:

    SecurityEvent | where EventID == 4625 | where TimeGenerated > ago(10m) | summarize FailedAttempts = count() by Account | where FailedAttempts > 5 -> Option A
  4. Quick Check:

    Filter by time + count > 5 per account = SecurityEvent | where EventID == 4625 | where TimeGenerated > ago(10m) | summarize FailedAttempts = count() by Account | where FailedAttempts > 5 [OK]
Hint: Filter time first, then count and filter by count > 5 [OK]
Common Mistakes:
  • Not filtering events by time range
  • Using incorrect logical operators in filters
  • Grouping by TimeGenerated causing wrong counts