nerdexam
Microsoft

AZ-500 · Question #595

Hotspot Question You have an Azure subscription. You configure Microsoft Sentinel to use multiple data sources. You need to create analytic rules that meet the following requirements: - Rule1…

This hotspot question tests knowledge of Microsoft Sentinel analytic rule types, specifically Threat Intelligence and Microsoft Security detection categories.

Submitted by emma.c· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

Hotspot Question You have an Azure subscription. You configure Microsoft Sentinel to use multiple data sources. You need to create analytic rules that meet the following requirements: - Rule1: Automatically match Common Event Format (CEF) logs and syslog data with domain, IP address, and URL indicators. - Rule2: Use Microsoft proprietary algorithms. Which type of detection should you use for each rule? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:

Exhibit

AZ-500 question #595 exhibit

Answer Area

  • Rule1:
    FusionMachine learning (ML) behavioral analyticsMicrosoft SecurityThreat intelligence
  • Rule2:
    FusionMachine learning (ML) behavioral analyticsMicrosoft SecurityThreat intelligence

Explanation

This hotspot question tests knowledge of Microsoft Sentinel analytic rule types, specifically Threat Intelligence and Microsoft Security detection categories.

Approach. Rule1 should use 'Threat Intelligence' (TI Map) detection type, because Threat Intelligence matching rules are specifically designed to automatically correlate CEF logs, syslog, and other data sources against threat intelligence indicators such as domain names, IP addresses, and URLs - this is their core purpose out-of-the-box. Rule2 should use 'Microsoft Security' (or 'Fusion' / 'ML Behavior Analytics') detection type - specifically 'Microsoft Security' rules leverage Microsoft's proprietary machine learning algorithms and threat detection logic built into products like Microsoft Defender for Endpoint, Azure AD Identity Protection, etc., producing alerts that Sentinel can consume; alternatively, 'Fusion' uses Microsoft's proprietary multi-stage attack detection ML algorithms, but the most precise answer here is that Microsoft Security rules use Microsoft proprietary algorithms sourced from Microsoft products, or Fusion which uses advanced multi-stage correlation ML from Microsoft.

Concept tested. Microsoft Sentinel analytic rule types: Threat Intelligence (TI map) rules automatically match log data (CEF/syslog) with IOC indicators (domain, IP, URL) imported from threat intelligence feeds, while Microsoft Security rules ingest alerts generated by Microsoft proprietary detection algorithms from services like Microsoft Defender, Azure Defender, and Azure AD Identity Protection - or Fusion rules use Microsoft's proprietary ML for multi-stage attack correlation.

Reference. https://learn.microsoft.com/en-us/azure/sentinel/threat-intelligence-integration and https://learn.microsoft.com/en-us/azure/sentinel/detect-threats-built-in

Topics

#Microsoft Sentinel#analytic rules#threat intelligence#machine learning analytics

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice