🔥 40% Off Crucial Exams Memberships — This Week Only

3 days, 13 hours remaining!

Microsoft Security Operations Analyst Associate SC-200 Practice Question

You create a scheduled analytics rule in Microsoft Sentinel that runs every five minutes. The query often returns many rows for the same user within an hour, and each row currently produces a separate incident. You need to reduce noise so that only one incident is created for each user during that hour without suppressing events for other users. Which rule setting should you configure?

  • Configure the Alert grouping section to combine alerts that share the same Account entity within a 1-hour window.

  • Enable alert suppression for 60 minutes after each trigger.

  • Change the rule scheduling frequency from 5 minutes to 60 minutes.

  • Set the alert threshold to require at least 12 query results before firing.

Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot