Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security engineer is investigating a potential data exfiltration incident. They need to identify all network connections from a specific virtual machine (VM) to external IP addresses over the past 24 hours. The VM's network interface has Network Watcher NSG Flow Logs enabled, sending data to a Log Analytics workspace. Which Kusto Query Language (KQL) operator should be used to extract only the source IP, destination IP, and destination port from the raw flow log data?

  1. Asummarize
  2. Bextend
  3. Cproject
  4. Djoin
Show answer & explanation

Correct answer: C. project

The `project` operator in KQL is used to select specific columns, rename them, or drop them from the query output. In this scenario, it would be used to select only the source IP, destination IP, and destination port columns from the NSG Flow Log data.

Why the other options are wrong

  • A. `summarize` is used for aggregation (e.g., counting, averaging), not for selecting specific columns.
  • B. `extend` is used to create new calculated columns, not simply select existing ones.
  • D. `join` is used to combine rows from two tables based on matching values in specified columns.

KQL 'project' Operator

A Kusto Query Language (KQL) operator used to select a subset of columns, rename columns, or reorder columns in the query result.

  • Essential for shaping query output to only relevant fields.
  • Can be used with `project-away` to remove columns, or `project-rename` to rename.
  • Improves readability and reduces data transfer size.

Memory trick: Project your desired Columns.

More Manage security operations questions