TechNuggets Academy

Configure protections and detections

Free Microsoft Certified: Security Operations Analyst Associate practice — 6 questions on Configure protections and detections, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Configure protections and detections
A SOC analyst needs a Sentinel analytics rule that correlates DeviceLogonEvents with SecurityEvent using a multi-stage join, aggregates results over a 6-hour window, and references a watchlist for known-bad IPs. The analyst initially builds this as an NRT (Near-Real-Time) rule, but the rule fails validation. What is the MOST likely reason and the correct fix?
NRT analytics rules are purpose-built for lightweight, fast-executing queries against a single data source that must complete within 60 seconds; they are not intended for complex multi-table joins with long lookback/aggregation windows. A Scheduled rule with an appropriate query frequency and lookup period is the correct tool for this requirement.
Question 2 of 6 · Configure protections and detections
A SOC needs to automatically raise the incident severity of any high-fidelity Fusion alert involving a compromised privileged account to High, and also correlate it with related low-severity anomaly alerts on the same account that occurred in the prior 48 hours. Which Sentinel feature combination BEST meets this requirement?
Fusion rules use machine learning to correlate low-fidelity signals — including UEBA anomaly detections — into a single high-fidelity multistage incident, but this correlation only works when entity mapping (Account, Host, IP) is consistently and correctly configured on the contributing analytics rules so Fusion can match entities across alerts.
Question 3 of 6 · Configure protections and detections
A Sentinel workspace has two automation rules scoped to the same analytics rule: Rule A (order = 1) sets status to 'Closed' with classification 'False Positive' for incidents whose title contains 'test'; Rule B (order = 2) runs a playbook that enriches every new incident with threat intelligence. Analysts report the enrichment playbook never runs on incidents titled 'test-alert'. What change correctly fixes this while preserving both rules' intended behavior?
Automation rules execute strictly in ascending order value. Since Rule A (order 1) closes the incident before Rule B (order 2) runs, giving Rule B a lower order number ensures the enrichment playbook executes first, and Rule A can still close the incident afterward — preserving both behaviors.
Question 4 of 6 · Configure protections and detections
An analytics rule frequently fires dozens of near-duplicate alerts for the same compromised host within a short period, flooding the incident queue with separate incidents. Which analytics rule setting should be configured to consolidate these into a single incident?
The Incident settings tab of an analytics rule includes an 'Alert grouping' configuration that lets you group alerts generated by that rule into a single incident when specified entities (such as Host) match within a defined time window — the correct, native way to reduce duplicate incidents from one rule.
Question 5 of 6 · Configure protections and detections
A Sentinel analyst wants to tune a built-in Anomaly detection rule by raising its sensitivity threshold to reduce false positives, but the Edit option for the built-in rule is greyed out for direct threshold changes. What is the correct approach?
Built-in anomaly detection rules are Microsoft-managed templates whose core logic can't be edited in place. The supported tuning workflow is to duplicate the rule, adjust threshold/multiplier settings on the copy, enable the duplicate, and disable the original so only the tuned version is active.
Question 6 of 6 · Configure protections and detections
An analyst creates a Microsoft Defender XDR custom detection rule against the CloudAppEvents table and wants to set the query frequency to 'Continuous (NRT)' for the fastest possible alerting, but that option is disabled in the rule wizard. What is the correct explanation and next step?
Continuous (NRT) frequency in Microsoft Defender XDR custom detection rules is only available for tables that support near-real-time evaluation; not all Advanced Hunting tables (including some cloud app event sources) support it. When unavailable, the analyst should select the fastest frequency the wizard actually allows for that table (commonly every 1 hour).
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code FREETEST33 — valid through Oct 6.

Get my $34.99 deal →