Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelHard

A security operations team is configuring Microsoft Sentinel to detect a sophisticated attack campaign that involves multiple, seemingly unrelated activities over an extended period. These activities, when viewed in isolation, might not trigger high-severity alerts, but their combination indicates a significant threat. Which type of analytics rule in Microsoft Sentinel is best suited to correlate these disparate activities into a single, high-fidelity incident?

  1. AFusion rules
  2. BMicrosoft security rules
  3. CNRT (Near Real-Time) rules
  4. DScheduled query rules
Show answer & explanation

Correct answer: A. Fusion rules

Fusion rules in Microsoft Sentinel are specifically designed to detect multi-stage attack campaigns by correlating low-fidelity alerts and activities from various data sources that, individually, might not seem significant. They use machine learning to identify complex, evolving threats.

Why the other options are wrong

  • B. Microsoft security rules are pre-built rules from Microsoft security services but don't offer the multi-stage, cross-source correlation capability of Fusion rules.
  • C. NRT rules provide faster detection for specific patterns but don't inherently perform multi-stage correlation across diverse event types.
  • D. Scheduled query rules are good for detecting specific patterns but struggle with correlating disparate, low-fidelity events over time without explicit complex queries.

Microsoft Sentinel Fusion Rules

Fusion rules are a built-in, AI-powered capability in Microsoft Sentinel that automatically detects multi-stage attacks by correlating alerts and activities from various products into single, high-fidelity incidents.

  • Uses machine learning for correlation.
  • Detects sophisticated, multi-stage attack campaigns.
  • Reduces alert fatigue by consolidating related low-fidelity alerts.

Memory trick: Fusion: Fuse the Faint into a Fiery Threat!

More Mitigate threats using Microsoft Sentinel questions