Courseiva
easyMultiple Choice

SC-200 Practice Question: A SOC analyst needs to create a custom alert in…

A SOC analyst needs to create a custom alert in Microsoft Sentinel that triggers when a specific user logs in from an unusual geographic location, compared to a learned baseline of normal locations. Which type of analytics rule is best suited for this scenario?

⚠ Common exam trap

A common mix-up: candidates confuse scheduled queries (Option A) with anomaly detection, assuming a KQL query using 'where Location != 'US'' can replace ML-based baseline learning, but scheduled queries cannot dynamically adapt to changing user behavior over time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Anomaly detection rule (machine learning)

Anomaly detection rules in Microsoft Sentinel use machine learning to establish a baseline of normal user behavior, such as typical geographic login locations. When a login event deviates significantly from this learned baseline, the rule triggers an alert. This is the only rule type specifically designed for detecting behavioral anomalies without requiring static thresholds or predefined patterns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Scheduled query

    Why it's wrong here

    A scheduled query rule executes a KQL query at a fixed frequency (e.g., every 15 minutes) and compares the result to a static threshold like a count or aggregation. This approach lacks adaptive learning of a user's typical sign-in pattern; any threshold you set will either be too strict or too permissive as the normal behavior shifts. Because it cannot dynamically establish a baseline, it is not the right choice for detecting a sign-in anomaly.

  • ✗

    Near-real-time (NRT) rule

    Why it's wrong here

    Near-real-time (NRT) rules run on streaming data in intervals as short as one minute, using explicitly defined conditions written in KQL. They are not backed by machine learning and do not maintain a baseline of historical behavior; every evaluation uses the same fixed criteria. Consequently, an NRT rule can catch fast signal but cannot identify subtle deviations from normal sign-in activity.

  • ✓

    Anomaly detection rule (machine learning)

    Why this is correct

    An anomaly detection rule using machine learning is the correct choice because it is purpose-built to learn a baseline of normal sign-in behavior for each user or entity. Using Microsoft Sentinel's ML analytics rules, the rule applies unsupervised learning to historical Microsoft Entra ID sign-in logs, then triggers when an event deviates significantly from that baseline (e.g., impossible travel or an unusual device). This matches the SOC analyst's need to create a custom alert for sign-in anomalies without manually specifying thresholds.

  • ✗

    Fusion rule

    Why it's wrong here

    Fusion rules are correlation-based analytics that ingest alerts from multiple sources (e.g., Microsoft Defender products, Identity Protection) to detect multi-stage attack chains, such as initial access followed by lateral movement. They do not evaluate a single sign-in against a learned baseline; instead they require multiple distinct signals to fire. Therefore, a Fusion rule cannot satisfy the requirement to alert on one anomalous sign-in event.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.