Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium
A security analyst needs to create a custom detection rule in Microsoft Sentinel that identifies anomalous login attempts from geographically disparate locations within a short timeframe. Which type of analytics rule is best suited for this scenario?
- ANRT (Near Real-time)
- BScheduled query
- CFusion
- DMicrosoft security
Show answer & explanationAnswer & explanation
Correct answer: B. Scheduled query
A Scheduled query analytics rule allows for running custom KQL queries at defined intervals (e.g., every 5 minutes, 1 hour) to detect specific patterns, such as anomalous login attempts. While NRT rules offer faster detection, 'anomalous login attempts from geographically disparate locations within a short timeframe' implies a need to aggregate and compare events over a window, which is a strength of scheduled queries.
Why the other options are wrong
- A. NRT rules are designed for ultra-low latency detection (every minute) but are generally for simpler, single-event or small-window detections, whereas complex geographical anomaly detection might benefit from a slightly longer lookback window often covered by scheduled queries.
- C. Fusion is a built-in rule that uses AI to combine multiple low-fidelity alerts into high-fidelity incidents, not for custom query-based detections.
- D. Microsoft security rules are built-in rules based on Microsoft's threat intelligence, not for custom logic.
Microsoft Sentinel Scheduled Query Analytics Rules
Custom detection rules in Sentinel that run a Kusto Query Language (KQL) query at specified intervals to identify security threats or anomalies.
- Offer flexibility for complex detection logic.
- Can aggregate data over a defined lookback period.
- Generate alerts and incidents based on query results.
Memory trick: Each rule type is a different 'detective' with a unique way of finding clues.