Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
05Configure your Microsoft Sentinel environment6 modules · 42 units · SIEM architecture, workspaces, logs, watchlists, threat intelligence, and unified SIEM/XDR0/42 units complete
Learning path 05 · Configure your Microsoft Sentinel environment

6 modules · 42 units · SIEM architecture, workspaces, logs, watchlists, threat intelligence, and unified SIEM/XDR

0%

Study focus

Sentinel foundation

Understand the SIEM workflow and design workspaces, permissions, retention, and data tiers.

Security context

Use logs, watchlists, threat intelligence, and Defender XDR integration to support operations.

6 modules · 42 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

03

Module 3

Query logs in Microsoft Sentinel

Focus: query surfaces, Sentinel feature tables, common connector tables, and Defender XDR advanced hunting schemas.
0/7
01 / 07Introduction

Analysts must recognize where connected data is stored and which table best answers an investigation question. Table names, schemas, retention, and portal query surfaces determine what KQL can access.

Official moduleLog query objectives
02 / 07Query logs in the logs page

In the Defender portal, use Advanced hunting for interactive analytics-tier queries and Data lake exploration for long-term data. In the Azure portal, use Sentinel's Logs page and switch the editor from Simple to KQL mode when required.

The query window exposes tables and fields, saved and sample queries, result columns, export, alert-rule creation, and incident linking. Always select the intended workspace and time range before interpreting results.

Official lessonAdvanced hunting, lake exploration, and Logs
03 / 07Understand Microsoft Sentinel tables
TablePurpose
SecurityAlertAlerts created by analytics rules or ingested directly from connectors.
SecurityIncidentIncident records that group one or more alerts.
ThreatIntelligenceIndicatorImported or manually created indicators such as IPs, domains, URLs, and hashes.
WatchlistImported watchlist records used for enrichment and correlation.

Analytics rules query workspace tables to create alerts; configured grouping and correlation then create incidents.

Official lessonSentinel feature tables
04 / 07Understand common tables
SourceCommon table
Azure control planeAzureActivity
Azure resource logsAzureDiagnostics
Microsoft Entra audit / sign-insAuditLogs, SigninLogs
Windows security / SysmonSecurityEvent, Event
Linux / network appliancesSyslog, CommonSecurityLog
Microsoft 365 auditOfficeActivity
Windows FirewallWindowsFirewall
Exam takeaway: choose the table from the data source and connector, not merely from the entity you are investigating.
Official lessonFrequently queried connector tables
05 / 07Understand Microsoft Defender XDR tables

Defender XDR advanced hunting tables are grouped by security domain. Endpoint examples include DeviceProcessEvents, DeviceNetworkEvents, DeviceFileEvents, DeviceLogonEvents, and DeviceRegistryEvents. Email examples include EmailEvents, EmailAttachmentInfo, EmailUrlInfo, and UrlClickEvents.

CloudAppEvents covers cloud application activity; identity tables cover sign-ins and directory behavior; AlertInfo and AlertEvidence connect detections to evidence. In the unified portal, these can be correlated with Sentinel workspace tables through advanced hunting according to onboarding and retention.

Official lessonDefender XDR advanced hunting schemas
06 / 07Module assessment

Match portal query surfaces and common tables to Sentinel alerts, incidents, Entra activity, Azure resources, Windows events, network devices, endpoints, identities, cloud apps, and email evidence.

Official assessmentTables and querying knowledge check
07 / 07Summary and resources

Start every investigation by confirming workspace, tier, time range, connector, and schema. Query the narrowest relevant table, then correlate across domains when the evidence requires it.

Official moduleSummary and resources
End of learning pathConfigure your Microsoft Sentinel environment