Microsoft Security Operations Analyst Associate SC-200 Practice Question
You create a scheduled analytics rule in Microsoft Sentinel to detect more than five failed Azure AD sign-in attempts from the same IP address. During testing, you discover that the rule produces a new incident for every single failed sign-in instead of one consolidated incident per source IP within a 4-hour window. Which change should you make in the rule configuration to ensure that all matching events from the same IP address within four hours are combined into a single incident?
Change the rule's schedule so the query frequency is four hours instead of its current value.
Enable suppression for four hours after each alert is generated.
Enable alert grouping and select to group by the IP address entity for a 4-hour grouping window.
Increase the query's lookup time range to four hours and leave alert grouping disabled.
When a scheduled analytics rule repeatedly matches events, you can avoid alert fatigue by turning on alert grouping. Choosing the option to group alerts into a single incident by an entity- in this case the IP address- causes Microsoft Sentinel to aggregate any alerts that share that entity during the specified grouping time frame (four hours). Merely expanding the query's time range or changing the frequency does not influence how Sentinel groups the resulting alerts, and suppressing notifications only hides them after they are generated; it does not prevent multiple incidents from being created in the first place.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is alert grouping in Microsoft Sentinel?
Open an interactive chat with Bash
How does selecting an entity like IP address impact alert grouping?
Open an interactive chat with Bash
What is the difference between alert grouping and suppression in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .