Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security operations center (SOC) team uses Microsoft Sentinel for SIEM. They want to create a custom rule to detect a specific type of attack pattern involving multiple failed login attempts followed by a successful login from a new, untrusted IP address within a 10-minute window. This requires correlating events from Azure AD sign-in logs. Which type of analytic rule in Microsoft Sentinel is best suited for this scenario?

  1. AFusion
  2. BMicrosoft security
  3. CAnomaly
  4. DScheduled query
Show answer & explanation

Correct answer: D. Scheduled query

A 'Scheduled query' analytic rule allows you to define a custom Kusto Query Language (KQL) query that runs at specified intervals. This is ideal for correlating multiple events over a time window, such as failed logins and subsequent successful logins from a new IP, to detect complex attack patterns.

Why the other options are wrong

  • A. Fusion rules use machine learning to automatically combine multiple low-fidelity alerts into high-fidelity incidents, but they are pre-built and not for custom KQL-based correlation of raw events.
  • B. Microsoft security rules are built-in rules generated by Microsoft security services (e.g., Defender for Cloud, Microsoft 365 Defender), not for custom correlation.
  • C. Anomaly rules use machine learning to detect unusual behavior. While useful, they are typically for detecting deviations from baselines, not for defining specific, complex attack patterns with strict time windows and correlation logic as described.

Sentinel Scheduled Query Rules

Analytic rules in Microsoft Sentinel that run custom Kusto Query Language (KQL) queries on a schedule to detect threats.

  • Enables detection of complex attack patterns and correlations.
  • Can be configured to generate incidents based on query results.
  • Supports various data sources ingested into Sentinel.

Memory trick: Sentinel's 'rules' are like different 'detectives' for threats.

More Manage security operations questions