Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security analyst is investigating a suspected data exfiltration incident from an Azure Storage Account. They need to analyze access logs to identify who accessed specific blobs, when, and from what IP address. The logs are currently being sent to a Log Analytics workspace. Which Kusto Query Language (KQL) operator should the analyst use to extract these specific fields while discarding all other columns from the query results for clarity and performance?

  1. Asummarize
  2. Bextend
  3. Cjoin
  4. Dproject
Show answer & explanation

Correct answer: D. project

The 'project' operator in KQL is used to select specific columns, rename them, or change their order in the output. It is highly effective for focusing on relevant data and improving query performance by reducing the amount of data processed and returned, which is crucial when investigating specific details like access patterns.

Why the other options are wrong

  • A. The 'summarize' operator is used to aggregate data, not to select specific columns for detailed viewing.
  • B. The 'extend' operator is used to create new computed columns, not to select or filter existing columns.
  • C. The 'join' operator is used to combine rows from two tables based on matching values in specified columns, not for column selection within a single table.

KQL project operator

A Kusto Query Language operator used to select, rename, and reorder columns in the output of a query.

  • Filters down to only the specified columns.
  • Improves readability and performance by reducing result set size.
  • Can be used to create new columns with simple expressions.

Memory trick: To 'project' a clear view, you 'cut' out the noise.

More Manage security operations questions