Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelHard
A security operations team is configuring Microsoft Sentinel to detect a sophisticated attack campaign that involves multiple, seemingly unrelated activities over an extended period. These activities, when viewed in isolation, might not trigger high-severity alerts, but their combination indicates a significant threat. Which type of analytics rule in Microsoft Sentinel is best suited to correlate these disparate activities into a single, high-fidelity incident?
- AFusion rules
- BMicrosoft security rules
- CNRT (Near Real-Time) rules
- DScheduled query rules
Show answer & explanationAnswer & explanation
Correct answer: A. Fusion rules
Fusion rules in Microsoft Sentinel are specifically designed to detect multi-stage attack campaigns by correlating low-fidelity alerts and activities from various data sources that, individually, might not seem significant. They use machine learning to identify complex, evolving threats.
Why the other options are wrong
- B. Microsoft security rules are pre-built rules from Microsoft security services but don't offer the multi-stage, cross-source correlation capability of Fusion rules.
- C. NRT rules provide faster detection for specific patterns but don't inherently perform multi-stage correlation across diverse event types.
- D. Scheduled query rules are good for detecting specific patterns but struggle with correlating disparate, low-fidelity events over time without explicit complex queries.
Microsoft Sentinel Fusion Rules
Fusion rules are a built-in, AI-powered capability in Microsoft Sentinel that automatically detects multi-stage attacks by correlating alerts and activities from various products into single, high-fidelity incidents.
- Uses machine learning for correlation.
- Detects sophisticated, multi-stage attack campaigns.
- Reduces alert fatigue by consolidating related low-fidelity alerts.
Memory trick: Fusion: Fuse the Faint into a Fiery Threat!