Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium
A Microsoft 365 administrator is configuring custom detection rules in Microsoft Defender XDR's Advanced Hunting. They need to create a rule that identifies attempts to disable security services on endpoints. The rule should trigger whenever a service named 'MsSense' (Microsoft Defender for Endpoint sensor) has its status changed to 'disabled' or 'stopped'. Which Kusto Query Language (KQL) operator should the administrator use to check if the 'ServiceState' field contains either 'disabled' or 'stopped'?
- A== (equality operator)
- Bmatches regex (regular expression operator)
- Ccontains (substring operator)
- Din (membership operator)
Show answer & explanationAnswer & explanation
Correct answer: D. in (membership operator)
The 'in' operator is used to check if a value exists within a list of possible values. In this scenario, it efficiently checks if 'ServiceState' is either 'disabled' or 'stopped' without needing multiple 'or' conditions.
Why the other options are wrong
- A. The '==' operator checks for exact equality with a single value, not multiple values in a list.
- B. The 'matches regex' operator is used for pattern matching with regular expressions, which is overkill and less readable for simple string comparisons against a fixed list.
- C. The 'contains' operator checks for a substring within a string; it's less efficient and not appropriate for checking exact matches against multiple distinct states.
KQL 'in' Operator
The KQL 'in' operator is a membership operator used to check if a scalar value matches any value in a provided list of scalar values.
- Syntax: `scalarExpression in (value1, value2, ...)`.
- Case-sensitive by default; use `!in` for 'not in' and `in~` for case-insensitive.
- Efficient for matching against multiple discrete values.
- Equivalent to multiple `or` conditions (e.g., `x == 'a' or x == 'b'`).
Memory trick: To check if a value is IN a LIST, use the 'in' operator.