Completion0%0 of 250 cards studied
Know00% of Study Deck
Unsure00% of Study Deck
Missed00% of Study Deck

Recommended Study Strategy

Round 1

Full Assessment

Go through all 250 Study Deck cards in order and grade each one Know, Unsure, or Missed. This sets your baseline.

Remaining: 250 cards

Start Round 1
Round 2

Review Deck

Study only the cards you graded Unsure or Missed. A card you grade Know leaves the Review Deck the next time you start a session.

Active pool: 0 cards

Open Review Deck
Round 3

Mastery Shuffle

Shuffle the full Study Deck and grade from memory to test what you really know.

Pass mark: 225 of 250 cards (90%)

Start Round 3

Study by Exam Domain

Exam Day Checklist

  • Match the question to the right hunting table: Device tables for endpoints, EmailEvents and UrlClickEvents for mail and Safe Links clicks, IdentityLogonEvents for Active Directory sign-ins, and AlertInfo with AlertEvidence for alerts.
  • Know the retention tiers: the Analytics tier keeps data ready for detections and hunting, while the Data lake tier stores it for up to 12 years and is reached through KQL jobs, Spark jobs, or summary rules.
  • Automation rules change incidents directly (status, severity, owner, tags, and tasks); anything that reaches another system needs a playbook, which is an Azure Logic Apps workflow.
  • Pick the ingestion path: Windows Security Events via AMA with a data collection rule for Windows hosts, and a forwarder with CEF via AMA (CommonSecurityLog) or Syslog via AMA (Syslog) for appliances.
  • Expect retired and moved features: Sentinel livestreams are gone (use KQL jobs, analytics rules, or playbooks), and Content search now lives inside eDiscovery.
  • Read the final sentence of a long scenario first to find the actual question.
  • Watch for qualifiers such as NOT, BEST, and MOST appropriate.
  • You have 100 minutes and need 700 to pass. Flag hard questions and come back; change an answer only with a clear reason.