A security engineer is investigating a Microsoft Sentinel incident that correlates multiple low-severity alerts into a high-confidence incident via the Fusion detection engine. The incident involves an anomalous Azure OpenAI usage spike following a compromised service principal sign-in. The engineer wants to understand how Fusion determined these alerts are related. Where can the engineer review the Fusion correlation logic?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because in the Microsoft Sentinel Incidents blade, clicking on a Fusion-generated incident and viewing the full details shows the correlated constituent alerts, the entities involved (IP addresses, user accounts, resources), and the timeline of events that Fusion's ML model determined were related. This is the primary interface for understanding why Fusion correlated specific alerts into a single incident.
Full explanation below image
Full Explanation
B is correct because in the Microsoft Sentinel Incidents blade, clicking on a Fusion-generated incident and viewing the full details shows the correlated constituent alerts, the entities involved (IP addresses, user accounts, resources), and the timeline of events that Fusion's ML model determined were related. This is the primary interface for understanding why Fusion correlated specific alerts into a single incident. A is incorrect because the Fusion rule in the Analytics blade shows the rule configuration and which alert scenarios Fusion covers, but the specific correlation reasoning for an individual incident is in the Incident details. C is incorrect because Microsoft Defender XDR incident graphs show attack chain visualization for XDR incidents, not for incidents generated by Sentinel Fusion correlating non-XDR alerts like Azure OpenAI diagnostics and Entra ID sign-in anomalies. D is incorrect because there is no 'Fusion correlation map' in the Threat Intelligence section; threat intelligence in Sentinel contains IOC indicators.