Microsoft Security Operations Analyst Associate SC-200 Practice Question
You are creating a scheduled analytics rule in Microsoft Sentinel that runs every 10 minutes and raises an alert whenever a known malicious file hash is observed on an endpoint. Security operations requires that any alerts raised by this rule during a six-hour window be consolidated into a single incident if they reference the same Hostname entity. In the rule wizard, which configuration must you modify to meet this requirement?
Configure a suppression rule that suppresses alerts from the same Hostname for six hours.
Change the query schedule so that the rule runs once every six hours instead of every 10 minutes.
Edit Incident settings and enable alert grouping by Entities using the Hostname entity with a six-hour grouping duration.
Create an automation playbook that merges incidents containing the same Hostname within six hours.
Microsoft Sentinel can automatically group alerts that originate from the same analytics rule into a single incident. In the rule wizard this is done in the Incident settings (also shown as Alert grouping). By enabling grouping by entities and selecting the Hostname entity with a six-hour grouping window, all alerts that share the same Hostname and are generated within that time span are merged into one incident.
A suppression rule temporarily prevents alerts from appearing at all; it does not merge them. Changing the query schedule to run every six hours would still create separate incidents for each run and would reduce detection timeliness. Playbooks and automation rules can modify incidents after they are created but are not required when the built-in alert grouping feature can perform the consolidation during incident creation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Incident settings in Microsoft Sentinel?
Open an interactive chat with Bash
What is the difference between suppression rules and alert grouping?
Open an interactive chat with Bash
How does alert grouping by entity work in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .