Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security operations team uses Azure Sentinel (now Microsoft Sentinel) for SIEM. They have integrated various data sources, including Azure Active Directory (Azure AD) sign-in logs and activity logs. To detect sophisticated threats that involve multiple stages and different data sources, they need to create custom detection rules that correlate events. Which type of rule in Sentinel is designed for this advanced correlation?

  1. AScheduled query rules
  2. BMachine learning behavior analytics rules
  3. CBasic analytics rules
  4. DFusion rules
Show answer & explanation

Correct answer: A. Scheduled query rules

Scheduled query rules in Microsoft Sentinel allow security analysts to write custom Kusto Query Language (KQL) queries that run on a schedule across multiple data sources. This enables the correlation of events from different logs to detect complex attack patterns or multi-stage threats.

Why the other options are wrong

  • B. Machine learning behavior analytics rules are often pre-built or leverage user behavior analytics (UBA) and are not primarily for custom multi-source correlation via KQL.
  • C. Basic analytics rules are not a specific type; 'Scheduled query rules' are the primary way to define custom analytics.
  • D. Fusion rules are built-in Sentinel rules that use machine learning to correlate low-fidelity alerts into high-fidelity incidents, but they are not custom-definable by the user.

Sentinel Scheduled Query Rules

Scheduled query rules in Microsoft Sentinel enable security analysts to define custom detection logic using Kusto Query Language (KQL). These rules run periodically against ingested log data to identify specific patterns, anomalies, or correlated events across multiple data sources, generating security incidents when triggered.

  • Uses KQL for custom detection logic.
  • Runs on a defined schedule (e.g., every 5 minutes).
  • Correlates events from various integrated data sources.
  • Generates incidents for investigation.

Memory trick: Schedule your queries to find the hidden threats.

More Manage security operations questions