You are configuring Microsoft Sentinel to detect potential ransomware activity. The security team wants to be alerted when a single host contacts multiple suspicious domains within a short time. Which analytic rule type should you create?
A Near-Real-Time (NRT) rule in Microsoft Sentinel evaluates the triggering query every minute with a maximum lookback of 30 minutes, using streaming analytics to preserve event ordering and timing. This enables you to catch rapid sequences of events—such as multiple failed logons immediately followed by a successful authentication—that would be missed by periodic batch processing. NRT rules are specifically engineered for low-latency, time-sensitive detections while still allowing KQL logic to match the exact pattern.
Why this answer
A NRT (Near-Real-Time) rule is the correct choice because it continuously processes events with a minimum latency of about 1 minute, making it ideal for detecting patterns like a single host contacting multiple suspicious domains within a short time window. Unlike scheduled rules that run on a fixed interval (e.g., every 5 minutes), NRT rules evaluate data as it arrives, enabling rapid detection of multi-event sequences such as DNS queries to known malicious domains.
Exam trap
The trap here is that candidates often confuse NRT rules with scheduled query rules, assuming a scheduled rule can achieve the same low latency by setting a short interval, but scheduled rules still incur a processing delay and cannot match the continuous streaming evaluation of NRT rules.
How to eliminate wrong answers
Option B (Scheduled query rule) is wrong because it runs on a predefined schedule (e.g., every 5 or 15 minutes), which introduces latency that could miss the tight time window required for detecting rapid multi-domain contacts. Option C (Anomaly rule) is wrong because it uses machine learning to baseline normal behavior and flag statistical outliers, not to match a specific pattern of a single host contacting multiple known suspicious domains. Option D (Microsoft security rule) is wrong because it ingests alerts from other Microsoft security products (e.g., Microsoft Defender for Endpoint) and does not allow custom detection logic based on raw event sequences like DNS queries.