Design security operations, identity, and compliance capabilities →mediumMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Sentinel and wants to correlate security events from multiple sources to detect multi-stage attacks. What should you create?
⚠ Common exam trap
Many exam-takers confuse scheduled query rules or NRT rules as the primary tool for correlation, but those require manual KQL logic to join data across sources, whereas Fusion provides automated, built-in multi-source correlation for multi-stage attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fusion rule
Fusion rules in Microsoft Sentinel are specifically designed to correlate security events from multiple sources and detect multi-stage attacks by combining alerts from different detection technologies into a single incident. This matches the requirement to correlate events across sources for complex attack chains, unlike other rule types that focus on single-source or single-event detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Scheduled query rule
Why it's wrong here
Scheduled query rules run on a fixed cadence (e.g., every 5 minutes) and execute a single KQL query against one data source. They can detect a specific event or pattern but cannot examine relationships across multiple alert types or data sources to reconstruct a multi-stage kill chain. Because Fusion's ML-based correlation is what links disparate low-fidelity alerts into a single incident, a scheduled rule lacks the intelligence required for multi-stage attack detection.
- ✗
NRT rule
Why it's wrong here
Near-real-time (NRT) rules execute a KQL query every minute, reducing alert latency compared to scheduled rules. However, each NRT rule still evaluates a single query against a single data source, and it does not apply machine learning to correlate alerts across different sign-in, behavior, or email signals. NRT rules are designed for rapid detection of a specific event, not for synthesizing a sequence of related alerts into a multi-stage attack story, so they are not the correct choice here.
- ✗
Anomaly rule
Why it's wrong here
Anomaly rules in Microsoft Sentinel use machine learning to establish baseline behavior for entities such as users or devices and then flag deviations from that baseline. While they can identify unusual single activities or entities, they do not combine multiple independent alerts from different sources to reveal an attack chain. In contrast, Fusion is specifically built to correlate unrelated low-fidelity alerts into a high-fidelity incident, making anomaly rules insufficient for multi-stage correlation.
- ✓
Fusion rule
Why this is correct
Fusion rules are built-in analytics rules in Microsoft Sentinel that use machine learning to correlate alerts from multiple Microsoft security products (e.g., Microsoft Defender for Identity, Defender for Office 365, Microsoft Entra ID Protection) into a single incident. The fusion engine maps alerts to MITRE ATT&CK stages, linking actions like initial access, lateral movement, and exfiltration into one coherent story. Because it automatically identifies multi-stage attack patterns without custom KQL, Fusion is the correct rule type for the organization's requirement to correlate multi-stage attacks.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.