Microsoft Security Operations Analyst Associate SC-200 Practice Question
While investigating incidents in Microsoft Sentinel, you discover that the "Impossible travel" analytic rule frequently opens multiple incidents for the same user within several hours. You need future alerts from this rule that involve the same user or IP address within an eight-hour window to be added to the existing incident instead of creating new incidents. Which configuration should you change?
The playbook assigned to the incident
An automation rule that runs when the incident is created
Alert grouping is configured in the analytic rule itself. By enabling grouping for alerts triggered by the rule and specifying entities (such as User or IP) with an eight-hour grouping duration, Microsoft Sentinel will append matching alerts to the current incident rather than create separate incidents. Automation rules and playbooks execute only after an incident already exists, so they cannot influence whether new incidents are opened. Data connector settings control how data is ingested but have no effect on incident grouping.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is alert grouping in Microsoft Sentinel?
Open an interactive chat with Bash
What is the difference between an analytic rule and an automation rule in Microsoft Sentinel?
Open an interactive chat with Bash
How do data connectors influence incidents in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .