Your SOC needs to detect excessive failed sign-ins within one minute and also detect sophisticated multi-stage attacks across signals from multiple Microsoft security products without writing custom correlation logic. What two configurations in Microsoft Sentinel should you implement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a near real-time (NRT) analytics rule that runs every minute to detect excessive failed sign-ins., Enable the built-in Fusion (Advanced Multistage Attack Detection) rule to automatically correlate multi-stage attacks across signals..
Why this is the answer
A near real-time (NRT) analytics rule is ideal for detecting excessive failed sign-ins within one minute because it runs queries every minute, providing the necessary rapid detection. The built-in Fusion (Advanced Multistage Attack Detection) rule in Microsoft Sentinel is specifically designed to automatically correlate sophisticated multi-stage attacks across various Microsoft security products without requiring custom correlation logic, fulfilling the second requirement. A scheduled analytics rule running every 5 minutes would not meet the "within one minute" requirement for failed sign-ins. While UEBA (User and Entity Behavior Analytics) enhances detection, it doesn't replace the need for specific rules like Fusion for multi-stage attack correlation and doesn't directly address the "without writing custom correlation logic" aspect for multi-stage attacks as effectively as Fusion. Livestream queries are for interactive, on-demand analysis, not for continuous, automated alerting like analytics rules.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed