Microsoft Security Operations Analyst Associate SC-200 Practice Question

While investigating incidents in Microsoft Sentinel, you discover that the "Impossible travel" analytic rule frequently opens multiple incidents for the same user within several hours. You need future alerts from this rule that involve the same user or IP address within an eight-hour window to be added to the existing incident instead of creating new incidents. Which configuration should you change?

  • An automation rule that runs when the incident is created

  • The data connector's grouping configuration

  • The playbook assigned to the incident

  • The alert grouping settings of the analytic rule

Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot