Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Sentinel and wants to correlate security events from multiple sources to detect multi-stage attacks. What should you create?

⚠ Common exam trap

Many exam-takers confuse scheduled query rules or NRT rules as the primary tool for correlation, but those require manual KQL logic to join data across sources, whereas Fusion provides automated, built-in multi-source correlation for multi-stage attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Fusion rule

Fusion rules in Microsoft Sentinel are specifically designed to correlate security events from multiple sources and detect multi-stage attacks by combining alerts from different detection technologies into a single incident. This matches the requirement to correlate events across sources for complex attack chains, unlike other rule types that focus on single-source or single-event detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Scheduled query rule

    Why it's wrong here

    Scheduled query rules run on a fixed cadence (e.g., every 5 minutes) and execute a single KQL query against one data source. They can detect a specific event or pattern but cannot examine relationships across multiple alert types or data sources to reconstruct a multi-stage kill chain. Because Fusion's ML-based correlation is what links disparate low-fidelity alerts into a single incident, a scheduled rule lacks the intelligence required for multi-stage attack detection.

  • NRT rule

    Why it's wrong here

    Near-real-time (NRT) rules execute a KQL query every minute, reducing alert latency compared to scheduled rules. However, each NRT rule still evaluates a single query against a single data source, and it does not apply machine learning to correlate alerts across different sign-in, behavior, or email signals. NRT rules are designed for rapid detection of a specific event, not for synthesizing a sequence of related alerts into a multi-stage attack story, so they are not the correct choice here.

  • Anomaly rule

    Why it's wrong here

    Anomaly rules in Microsoft Sentinel use machine learning to establish baseline behavior for entities such as users or devices and then flag deviations from that baseline. While they can identify unusual single activities or entities, they do not combine multiple independent alerts from different sources to reveal an attack chain. In contrast, Fusion is specifically built to correlate unrelated low-fidelity alerts into a high-fidelity incident, making anomaly rules insufficient for multi-stage correlation.

  • Fusion rule

    Why this is correct

    Fusion rules are built-in analytics rules in Microsoft Sentinel that use machine learning to correlate alerts from multiple Microsoft security products (e.g., Microsoft Defender for Identity, Defender for Office 365, Microsoft Entra ID Protection) into a single incident. The fusion engine maps alerts to MITRE ATT&CK stages, linking actions like initial access, lateral movement, and exfiltration into one coherent story. Because it automatically identifies multi-stage attack patterns without custom KQL, Fusion is the correct rule type for the organization's requirement to correlate multi-stage attacks.

About these practice questions

This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.