SC-200 Lab 5 – Kusto Query Language (KQL)

Microsoft Security Operations Analyst — Lab 5

Lab 5 – Kusto Query Language (KQL)

SC-200: Microsoft Security Operations Analyst

Overview


Built KQL query skills using the Microsoft Sentinel Training Lab workspace and Microsoft Learn exercises. Covered basic statements through advanced multi-table joins, data visualization, and string manipulation — all foundational skills for writing detection rules and hunting queries in Sentinel.

KQL lab structure: Microsoft Sentinel Training Lab Workspace with 7 tasks covering basic statements through string data operations
Lab architecture diagram — Source: MicrosoftLearning/SC-200T00A-Microsoft-Security-Operations-Analyst, MIT License

Tasks Completed


Environment: Employer-provided Azure subscription (resources deleted after lab).

Source Material


Completed using Lab 5 – Exercise 1: Create KQL Queries for Microsoft Sentinel from the SC-200T00A MicrosoftLearning GitHub repository; and Microsoft Learn exercises Connect to Resources, Return Rows with the Take Operator, Query Data Setup, and Visualize Data in Sentinel. Completed in an employer-provided Azure subscription.