CyberHire

Skills test for hiring

KQL and Microsoft Sentinel test for hiring

A hands-on KQL test that shows who can actually hunt. Candidates write real queries against sign-in, device and audit tables in a Sentinel-style workspace, with nothing labelled, and have to find the attacker in the data.

9 hands-on challenges · 20 to 40 minutes each · Built around your job spec

portal.cyber-hire.com/challenge/kql Microsoft Sentinel
KQL skills test: a KQL lab titled Full Kill Chain Investigation, with a Sentinel-style query editor beside a schema pane listing SigninLogs, DeviceEvents and AuditLogs, 405 sign-in records returned, and a free-text question asking which account was the initial point of compromise.

What candidates actually do

The work itself. Not questions about it.

Candidates work in environments that look like the job, on realistic data with legitimate activity left in. The answer only exists in the data in front of them, so there is nothing to look up and nothing to guess between.

  • Sentinel-style KQL workspace
  • SigninLogs
  • Device and process events
  • Audit logs
Sample task KQL workspace

KQL Lab: Password Spray and Privilege Escalation

An attacker sprayed passwords against the tenant, then escalated privileges with an account they took over. Using the sign-in and alert tables, find the source IP address of the spray, then the account that was compromised.

What a strong answer shows

Counts distinct accounts with failed sign-ins per source address in a time window, rather than failures per account, then follows the successful sign-in through to the privilege change. A weak answer stalls at the schema or reports the noisiest IP.

Skills covered

9 real challenges. Pick the ones that fit the role.

Every assessment is assembled from the library to match your job spec, then calibrated to the level you are hiring. These are the KQL and Sentinel challenges it draws on.

Identity and sign-in investigation

  • KQL Lab: Suspicious Sign-In Investigation Medium 25 min
  • KQL Lab: Password Spray & Privilege Escalation Hard 30 min
  • KQL Lab: MFA Bypass & Token Replay Detection Hard 30 min

Endpoint and logon hunting

  • KQL Lab: Windows Logon Forensics Medium 20 min
  • KQL Lab: Endpoint Threat Detection Medium 25 min

Email and data threats

  • KQL Lab: Phishing Campaign Detection Medium 20 min
  • KQL Lab: Insider Threat - Data Exfiltration Medium 25 min

End-to-end investigation

  • KQL Lab: Full Kill Chain Investigation Expert 40 min

Detection rule review

  • Detection Review Board - Sentinel Analytics Rule Medium 22 min

Levels: 6 Medium · 2 Hard · 1 Expert. Assessments usually combine a few challenges to fit the time you set.

What you get back

Evidence for every candidate. Scored the same way.

Every candidate is scored against the same answers, so you compare the work, not impressions. Read a candidate in two minutes, then interview the ones who can do the job.

  1. A score per skill See where each candidate is strong and where they are thin, not just a single number.
  2. Their actual answers Read what they found and how they explained it, so you can probe it in the interview.
  3. Integrity signals Time away, outside pasting, fullscreen exits and second screens, next to every score.

Common questions

About the KQL and Sentinel test.

What does the KQL test measure?

Whether a candidate can use KQL to investigate real activity: finding suspicious sign-ins, password sprays, token replay, endpoint threats and data exfiltration across sign-in, device and audit tables. The answer has to be found in the data, not recalled.

Is this a real Microsoft Sentinel instance?

It is a Sentinel-style KQL workspace with realistic tables such as SigninLogs, device events and audit logs, built for assessment. Candidates write real KQL against it; they do not need access to your environment.

Who should take a KQL test?

SOC analysts, threat hunters and detection engineers working in Microsoft security tools. For broader SOC roles, combine it with email and event log challenges in the SOC analyst test.

How long does it take?

Most labs take 20 to 30 minutes; the end-to-end kill chain investigation takes about 40. You choose which labs to include to fit the time you want.

Try it on your role

See the KQL and Sentinel test built for your job spec.

Send us the job spec for a role you are hiring. Within 48 hours we send you a hands-on assessment built around it, in your brand, to try for yourself. Free, and with no commitment.