KQL ExamQuestions
KQL ExamQuestions
Questions
1) Detect Failed Logins from SignIn table
2) Write KQL for Computers with logons from guest accounts from Security
Events Table
3) Write KQL for Logons with clear text password by target account.
4) Write KQL to look into Syslog for computers with failed sudo login.
5) Write KQL to Count how many security or other critical updates are
missing using Update table.
6) Identify Admin Activities in Azure Activity Table using KQL
7) Identify Failed Login Attempts in past 1 hour in Azure Activity Table using
KQL