Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium
A security engineer is investigating a potential data exfiltration incident. They need to analyze diagnostic logs from an Azure Storage Account that contains sensitive data. Specifically, they want to filter the logs to show only 'Read' operations performed by non-trusted IP addresses and project only the 'time', 'caller IP address', and 'operation name' fields. Which Kusto Query Language (KQL) operator should be used to select specific columns for display?
- Ajoin
- Bsummarize
- Cextend
- Dproject
Show answer & explanationAnswer & explanation
Correct answer: D. project
The 'project' operator in KQL is used to select a subset of columns to include in the output, effectively shaping the table to only show the desired fields.
Why the other options are wrong
- A. Join combines rows from two tables based on a common value, not for selecting columns from a single table.
- B. Summarize aggregates data, it does not select specific columns for display.
- C. Extend adds new computed columns to the table, it does not select existing columns for display.
KQL 'project' operator
The Kusto Query Language (KQL) 'project' operator selects specific columns from a table to include in the output, allowing for column renaming and reordering.
- Used to shape the output table.
- Can include, rename, and reorder columns.
- Essential for focusing on relevant data fields.
Memory trick: Project 'projects' only the columns you need.