AZ-500 Manage identity and access Practice Question
A Microsoft Sentinel rule should run with minimal delay against supported data sources and produce alerts close to event time. Which rule type should be considered?
⚠ Common exam trap
Watch out — candidates often confuse near-real-time rules with scheduled analytics rules, assuming scheduled rules can be configured for minimal delay, but NRT rules are the only type that guarantees sub-5-minute latency without custom scheduling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Near-real-time analytics rule
Near-real-time (NRT) analytics rules in Microsoft Sentinel are designed to run at 1-minute intervals, providing the minimal delay for alert generation against supported data sources. This rule type queries data with low latency, ensuring alerts are produced close to the event time, which is critical for timely threat detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fusion rule
Why it's wrong here
Fusion rules are Microsoft Sentinel correlation detections that combine alerts from multiple products and low-fidelity signals into a single high-fidelity incident. They operate on a machine-learning correlation process that waits for several precursor alerts to be generated, so by design they introduce delay rather than providing minimal-latency evaluation of a single telemetry stream. Thus a Fusion rule is inappropriate when the requirement is to run immediately against incoming data with the least possible lag.
- ✓
Near-real-time analytics rule
Why this is correct
A near-real-time (NRT) analytics rule is executed once every minute against data that was ingested in the previous minute, so it provides the smallest detection-to-action delay of all Microsoft Sentinel rule types. Unlike scheduled analytics rules whose query interval is often 5 minutes or more, NRT rules are explicitly designed for time-sensitive use cases and can trigger automation immediately. This is why they are the correct choice for a rule that must run with minimal delay.
- ✗
Workbook query
Why it's wrong here
Workbook queries are interactive Azure Monitor workbooks that visualize and explore data when a user opens or refreshes the workbook; they are not detection rules and do not run on a schedule. Because workbook execution is user-driven and purely for analysis, it cannot continuously evaluate incoming telemetry or generate alerts with minimal delay. Selecting a workbook query as a “rule” would mean relying on manual refresh, which is the opposite of automated minimal-latency detection.
- ✗
Threat intelligence indicator import
Why it's wrong here
Threat intelligence (TI) indicator import is an ingestion process that brings indicators of compromise into Sentinel from sources such as TAXII feeds or Microsoft Graph Security API. While imported indicators can feed detection rules such as TI-match analytics, the import operation itself is not a rule that runs against live data with minimal delay to produce alerts. It merely updates the TI tables and therefore does not satisfy the requirement for a low-latency, automatically running detection rule.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.