Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRHard

A Microsoft 365 administrator is configuring a custom alert rule in Microsoft Defender XDR to detect anomalous activities. The rule needs to trigger an alert if a user successfully logs in from a country that is not part of the organization's approved list of operational countries, and then, within 30 minutes, attempts to access sensitive SharePoint Online data. The administrator plans to use Kusto Query Language (KQL) for this. Which KQL operator is essential for correlating these two distinct events (login and data access) based on a common user and within a specified time window?

  1. A`join`
  2. B`mv-expand`
  3. C`union`
  4. D`fork`
Show answer & explanation

Correct answer: A. `join`

The `join` operator in KQL is used to combine rows from two or more tables based on a common column. When combined with `on` and `kind=innerunique` or `kind=leftouter` and `where` clauses, it can effectively correlate events within a time window for the same user.

Why the other options are wrong

  • B. `mv-expand` expands multi-value dynamic arrays or property bags into separate rows, which is irrelevant for correlating distinct events across tables.
  • C. `union` combines the rows of two or more tables with compatible schemas into a single table, it does not correlate events based on common fields or time windows.
  • D. `fork` is not a standard KQL operator for correlating data across tables; it's used in some contexts for parallel execution or branching, but not for this scenario.

KQL Join Operator

The `join` operator in Kusto Query Language (KQL) combines rows from two or more tables based on matching values in specified common columns, enabling the correlation of related events or data points.

  • Combines rows from different tables.
  • Requires a common column for matching.
  • Supports various join kinds (inner, leftouter, rightouter, etc.).
  • Essential for correlating events over time.

Memory trick: Correlating events means linking them by commonalities, especially over time.

More Implement and manage Microsoft Defender XDR questions