Microsoft Security Operations Analyst Associate SC-200 Practice Question
You created a Microsoft Sentinel hunting query that identifies suspicious downloads by joining AzureActivity and AzureDiagnostics tables. During testing, the query returns the same records every time you run it, even though you already tagged the previous results as investigated. You need to modify the Kusto Query Language (KQL) statement so that future executions return only records that have not yet been reviewed and bookmarked. Which KQL operator should you add to the query to meet this requirement?
The anti join operator excludes records in the left table that also appear in the right table. In a hunting scenario, you can join the live data set (for example, AzureActivity) with the SecurityAlert or HuntingBookmark tables that contain events you have already triaged. By performing a left-anti join, the query outputs only new, un-bookmarked events. Other joins such as innerunique or inner return matching rows rather than excluding them, while union combines sets without filtering duplicates. The project-away statement merely removes columns and does not prevent previously investigated events from reappearing.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does the 'join kind=leftanti' operator do in KQL?
Open an interactive chat with Bash
How is 'join kind=leftanti' different from other join types in KQL?
Open an interactive chat with Bash
Why is 'join kind=leftanti' vital for hunting queries in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .