Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelHard

A security analyst is creating a new analytics rule in Microsoft Sentinel to detect a sophisticated attack pattern. The attack involves multiple distinct events occurring within a short timeframe, but not necessarily in a strict sequential order. The analyst needs to correlate these events from different tables into a single incident. Which type of analytics rule is best suited for this scenario?

  1. ANRT (Near Real-time) rule
  2. BFusion rule
  3. CMicrosoft Security rule
  4. DScheduled query rule
Show answer & explanation

Correct answer: B. Fusion rule

Fusion rules in Microsoft Sentinel use machine learning to correlate low-fidelity alerts and behavioral anomalies across multiple data sources into high-fidelity incidents, making them ideal for detecting complex, non-linear attack patterns.

Why the other options are wrong

  • A. NRT rules are a type of scheduled query rule optimized for low-latency detection, but they still rely on explicit KQL and don't inherently perform the multi-stage, non-linear correlation of Fusion rules.
  • C. Microsoft Security rules are pre-built rules from Microsoft security services (like Defender for Cloud) and don't allow custom correlation logic for sophisticated attack patterns.
  • D. Scheduled query rules run KQL queries on a schedule and are good for specific detections, but less effective for complex, multi-stage, non-linear attack patterns across different tables without explicit KQL logic for each stage.

Microsoft Sentinel Fusion Rules

Fusion rules are built-in analytics rules in Microsoft Sentinel that use machine learning to automatically detect multi-stage attacks by correlating disparate alerts and behavioral anomalies across various data sources.

  • Uses machine learning for correlation.
  • Detects multi-stage, sophisticated attacks.
  • Correlates low-fidelity alerts into high-fidelity incidents.

Memory trick: To 'Fuse' together many small clues into one big attack, use Fusion rules.

More Mitigate threats using Microsoft Sentinel questions