
Exam preparation hub
Microsoft · Associate
Microsoft Security Operations Analyst
Try it free
Submit your answer to see the reasoning for every option, key learning points, and related services.
Practice Questions 1
You have a Microsoft 365 E5 subscription and a Microsoft Sentinel workspace.
You need to create a KQL query that will combine data from the following sources:
• Microsoft Graph • Risky users detected by using Microsoft Entra ID Protection
The solution must minimize the volume of data returned.
How should the query start?
Use the exam weights to decide which domains to study first.