Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium

A security analyst needs to create a custom detection rule in Microsoft Sentinel that identifies anomalous login attempts from geographically disparate locations within a short timeframe. Which type of analytics rule is best suited for this scenario?

  1. ANRT (Near Real-time)
  2. BScheduled query
  3. CFusion
  4. DMicrosoft security
Show answer & explanation

Correct answer: B. Scheduled query

A Scheduled query analytics rule allows for running custom KQL queries at defined intervals (e.g., every 5 minutes, 1 hour) to detect specific patterns, such as anomalous login attempts. While NRT rules offer faster detection, 'anomalous login attempts from geographically disparate locations within a short timeframe' implies a need to aggregate and compare events over a window, which is a strength of scheduled queries.

Why the other options are wrong

  • A. NRT rules are designed for ultra-low latency detection (every minute) but are generally for simpler, single-event or small-window detections, whereas complex geographical anomaly detection might benefit from a slightly longer lookback window often covered by scheduled queries.
  • C. Fusion is a built-in rule that uses AI to combine multiple low-fidelity alerts into high-fidelity incidents, not for custom query-based detections.
  • D. Microsoft security rules are built-in rules based on Microsoft's threat intelligence, not for custom logic.

Microsoft Sentinel Scheduled Query Analytics Rules

Custom detection rules in Sentinel that run a Kusto Query Language (KQL) query at specified intervals to identify security threats or anomalies.

  • Offer flexibility for complex detection logic.
  • Can aggregate data over a defined lookback period.
  • Generate alerts and incidents based on query results.

Memory trick: Each rule type is a different 'detective' with a unique way of finding clues.

More Mitigate threats using Microsoft Sentinel questions