Courseiva

SC-200 Respond to security incidents Practice Question

Your security operations center (SOC) uses Microsoft Sentinel. An incident is created from a fusion alert. What does Fusion technology do?

⚠ Common exam trap

The trap is confusing Fusion with UEBA or scheduled analytics rules — Fusion is specifically the cross-product, multi-stage attack correlation engine, not a behaviour-analytics or query-scheduling feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Correlates alerts from different products to detect multi-stage attacks

Microsoft Sentinel's Fusion technology is a correlation engine that stitches together low-fidelity alerts and signals from multiple sources (Microsoft and third-party products) into high-fidelity incidents representing multi-stage attacks. It uses machine learning models built on attack kill-chain patterns to detect sequences like a suspicious sign-in followed by anomalous resource creation. This is why Fusion incidents are typically high severity and span multiple products.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Uses machine learning to detect suspicious user behavior

    Why it's wrong here

    Fusion correlates multiple low-fidelity signals across different products into a single high-severity incident, rather than profiling individual user activity. User and entity behaviour analytics (UEBA) in Microsoft Sentinel performs the anomaly detection described here, and would be the right answer if the question asked how unusual sign-in or data-access patterns are surfaced.

  • ✗

    Runs queries at scheduled intervals to detect threats

    Why it's wrong here

    Scheduled query rules execute analytics at set intervals, which is what custom scheduled analytics rules do — not Fusion. Fusion correlates low-fidelity signals across multiple products into a single high-severity incident, so it detects multi-stage attacks rather than running periodic queries. Scheduled rules would be correct when you need recurring KQL-based detection on a defined cadence.

  • ✗

    Detects unusual patterns in Azure activity logs

    Why it's wrong here

    Fusion correlates low-fidelity signals across multiple products into a single high-severity incident, so it does not itself scan Azure activity logs for anomalies. That describes Microsoft Sentinel's built-in analytics rules or Microsoft Entra ID Protection detections, which suit standalone suspicious-activity monitoring rather than cross-domain multistage attack detection.

  • ✓

    Correlates alerts from different products to detect multi-stage attacks

    Why this is correct

    Fusion correlation in Microsoft Sentinel links low-fidelity alerts and anomalies across multiple products into a single incident, identifying multi-stage attack progressions that individual detections miss. This directly satisfies the stem's fusion alert scenario, where the SOC receives one consolidated incident rather than separate, unrelated alerts.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.