3: Analytics Rules Flashcards

(15 cards)

1
Q

What is an analytics rule in Microsoft Sentinel?

A

It’s a scheduled query that scans your logs for suspicious patterns and generates alerts when those patterns are detected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Where do you configure analytics rules?

A

Microsoft Sentinel > [Workspace] > Analytics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What types of analytics rules exist in Sentinel?

A

Scheduled, Microsoft Security (automatic Defender integrations), Fusion (AI-driven correlation), and NRT (near-real-time) rules.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a scheduled rule?

A

A custom rule you define using KQL to detect specific behaviors on a regular interval.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a Fusion rule?

A

A Microsoft-built rule that uses machine learning to correlate low-fidelity signals into high-confidence multistage attack incidents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What happens when a rule is triggered?

A

An alert is created, and if configured, Sentinel can group it into an incident and/or trigger a playbook.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What’s the difference between an alert and a rule?

A

A rule defines the logic; an alert is the result of the rule firing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can you customize the logic of built-in analytics rules?

A

Yes, most prebuilt rules can be cloned and modified to suit your environment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Why are analytics rules important?

A

They automate detection so you can catch threats early and reduce reliance on manual log review.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What should I tune in a rule to reduce noise?

A

Look at the frequency, thresholds, KQL filters, and suppression logic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Can I map my rules to MITRE ATT&CK?

A

Yes, you can tag rules with relevant MITRE tactics and techniques.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the value of Fusion rules?

A

They surface complex attack paths by connecting seemingly unrelated signals—great for detecting lateral movement or multi-stage attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What’s the benefit of using Microsoft Security rules?

A

They automatically surface high-confidence alerts from Microsoft Defender tools without needing custom queries.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Can analytics rules trigger automation?

A

Yes, you can attach playbooks to alerts generated by rules.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Why should customers care about analytics rules?

A

They turn raw logs into real-time detection, helping reduce response time and catch threats that would otherwise go unnoticed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly