Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium
A security operations center (SOC) uses Azure Sentinel for monitoring. They have configured a custom analytics rule that uses a Kusto Query Language (KQL) query to detect unusual administrative logins. This rule generates a high volume of false positives due to legitimate, but infrequent, administrative activities. Which of the following is the most effective way to reduce false positives without missing actual threats?
- ADisable the analytics rule and rely on other built-in Sentinel rules.
- BRefine the KQL query to include additional filtering criteria or baselines for legitimate activity.
- CDecrease the query's lookback period to reduce the data analyzed.
- DIncrease the alert threshold to require more events before triggering.
Show answer & explanationAnswer & explanation
Correct answer: B. Refine the KQL query to include additional filtering criteria or baselines for legitimate activity.
Refining the KQL query to incorporate additional filtering criteria, baselines, or behavioral analytics (e.g., specific source IPs for administrators, time-of-day restrictions, or known administrative jump boxes) is the most effective way to reduce false positives while maintaining detection capability for actual threats. This makes the detection logic more precise.
Why the other options are wrong
- A. Disabling the rule would eliminate detection for that specific threat, which is unacceptable for a high-severity alert type.
- C. Decreasing the lookback period might miss slower, more stealthy attacks, and doesn't address the root cause of the false positive logic.
- D. Increasing the threshold might suppress legitimate threats if they fall below the new count, and doesn't make the detection logic smarter.
Sentinel KQL Query Optimization
The process of improving Kusto Query Language (KQL) queries in Azure Sentinel analytics rules to enhance detection accuracy, reduce false positives, and improve performance.
- Involves adding specific filters, exclusions, or behavioral baselines.
- Aims to distinguish between legitimate activity and malicious behavior.
- Crucial for maintaining an effective and actionable SIEM.
Memory trick: Refine the KQL to Filter the Noise.