nerdexam
Microsoft

SC-200 · Question #142

You have a Microsoft Sentinel workspace. You need to identify which rules are used to detect advanced multistage attacks that comprise two or more alerts or activities. The solution must minimize…

The correct answer is A. Fusion. Microsoft Sentinel uses Fusion, a correlation engine based on scalable machine learning algorithms, to automatically detect multistage attacks. https://learn.microsoft.com/en-us/azure/sentinel/fusion

Submitted by saadiq_pk· Apr 18, 2026Detect and remediate threats using Microsoft Sentinel

Question

You have a Microsoft Sentinel workspace. You need to identify which rules are used to detect advanced multistage attacks that comprise two or more alerts or activities. The solution must minimize administrative effort. Which rule type should you query?

Options

  • AFusion
  • BMicrosoft Security
  • CML Behavior Analytics
  • DScheduled

How the community answered

(29 responses)
  • A
    90% (26)
  • B
    7% (2)
  • C
    3% (1)

Explanation

Microsoft Sentinel uses Fusion, a correlation engine based on scalable machine learning algorithms, to automatically detect multistage attacks. https://learn.microsoft.com/en-us/azure/sentinel/fusion

Topics

#Microsoft Sentinel#Fusion rules#Multistage attack detection#Incident correlation

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice