Using Fusion Rules for Multi-Signal Incident Correlation in Microsoft Sentinel
A financial services company uses Microsoft Sentinel to detect ransomware activity. They want to correlate alerts from multiple sources to reduce false positives. They have enabled Microsoft Defender for Cloud, Microsoft Defender XDR, and Azure Firewall logs. Which Sentinel feature should they use to create a single alert from multiple signals?
⚠ Common exam trap
It's easy for candidates to confuse Fusion rules with Scheduled query rules, thinking they can manually write KQL to correlate alerts, but Fusion's machine learning correlation is automatic and purpose-built for multi-source alert fusion, which is exactly what the scenario requires.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fusion (machine learning) rules
Fusion (machine learning) rules in Microsoft Sentinel are specifically designed to correlate alerts from multiple sources—such as Microsoft Defender for Cloud, Microsoft Defender XDR, and Azure Firewall logs—by using machine learning models to identify multi-stage attack patterns and reduce false positives. This makes Fusion the correct choice for creating a single alert from multiple signals, as it automatically combines related alerts into a single, high-fidelity incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Near-real-time (NRT) rules
Why it's wrong here
Near-real-time (NRT) rules in Microsoft Sentinel are designed for low-latency detection, running queries as often as every minute to catch urgent threats. However, they operate on a single table or a limited set of tables and do not have the capability to correlate alerts across different data sources or product feeds. In a multi-stage attack, an NRT rule would flag only one isolated indicator (e.g., a suspicious sign-in) without linking it to subsequent lateral movement or data exfiltration, so it cannot reconstruct the full attack chain. Their low-latency benefit does not compensate for the lack of cross-source correlation needed for this scenario.
- ✓
Fusion (machine learning) rules
Why this is correct
Fusion (machine learning) rules are specifically built for detecting multi-stage attacks by correlating alerts from multiple products, such as Microsoft Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud. The engine uses scalable machine learning algorithms to analyze incoming alerts, identify patterns that match known kill-chain sequences, and automatically fuse them into a single actionable incident with a story of the attack. This goes beyond simple alert aggregation: Fusion evaluates the timing, context, and relationships between alerts to produce high-fidelity incidents with low false-positive rates. Because the scenario requires detecting a multi-stage attack that spans various alert sources, Fusion is the correct choice.
- ✗
Anomaly detection rules
Why it's wrong here
Anomaly detection rules in Microsoft Sentinel employ machine learning to establish baseline behavior and then flag deviations, such as an unusual number of sign-ins or abnormal process execution. They are inherently univariate or simple multivariate outlier detectors and do not perform correlation of distinct alerts from different sources to identify a coordinated attack sequence. In a multi-stage attack, an anomaly rule might surface one stage as an outlier, but it will not automatically connect that anomaly to other stages or generate a consolidated incident. Thus, anomaly rules are useful for spotting suspicious behavior but not for stitching together a multi-stage kill chain.
- ✗
Scheduled query rules
Why it's wrong here
Scheduled query rules run KQL queries against one or more tables at predefined intervals (for example, every 5 minutes to every 14 days) and raise alerts when query results match their logic. While a skilled analyst could write a KQL query that joins across multiple tables to simulate correlation, this is a manual, deterministic approach that lacks the built-in intelligence to automatically recognize and fuse heterogeneous alert types from different products. These rules are static and do not scale or adapt to new attack patterns the way Fusion's machine learning does, nor do they have the cross-product alerting capability. Therefore, scheduled queries are not the appropriate automated solution for detecting multi-stage attacks in this context.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.