AZ-500 Manage identity and access Practice Question
A Sentinel analytics rule creates a new incident every time the same brute-force activity is detected for the same account within an hour. The SOC wants one incident that continues to group related alerts. What should be changed?
⚠ Common exam trap
Watch out — candidates often confuse incident grouping with alert suppression or think that disabling entity mapping will reduce noise, but entity mapping is actually required for grouping to work correctly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure incident grouping in the scheduled analytics rule
Incident grouping in a scheduled analytics rule allows multiple alerts triggered by the same entity (e.g., the same account) within a specified time window to be combined into a single incident. By configuring the 'Group related alerts into a single incident' setting and setting the grouping window to one hour, the SOC ensures that all brute-force alerts for the same account are merged into one incident, reducing alert fatigue and providing a consolidated view of the attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable entity mapping for the account entity
Why it's wrong here
Disabling entity mapping for the account entity removes the account's contextual data from the alert, but incident creation is governed by the rule's alert grouping and incident settings, not by entity mappings. Without entity mapping, Sentinel cannot correlate alerts by that account, so each qualifying alert may still generate its own incident rather than consolidating them. This does not reduce incident volume; it only degrades investigation and automation capabilities.
- ✓
Configure incident grouping in the scheduled analytics rule
Why this is correct
Configuring incident grouping in the scheduled analytics rule lets you define how alerts from the same rule are grouped into incidents, such as by matching entities (e.g., account) or within a specific time window. When grouping is set to 'Group all alerts into a single incident' or based on entity mapping, Sentinel will not create a new incident for every alert that fires. This directly satisfies the requirement to avoid a new incident each time the same entity triggers the rule.
- ✗
Change the rule query to use project-away on TimeGenerated
Why it's wrong here
Using project-away on TimeGenerated removes the TimeGenerated column from the rule's query result, but TimeGenerated is a system-generated timestamp that Sentinel uses for time-based correlation and scheduling. Removing it does not affect the rule's incident creation behavior because incident grouping is controlled by the rule's 'Event grouping' configuration, not by the presence of that column in the output. In fact, omitting TimeGenerated may break time-window alignment and cause unexpected alert behavior, making this option counterproductive.
- ✗
Run the rule as a near-real-time rule
Why it's wrong here
Running the rule as a near-real-time (NRT) rule changes the execution frequency to every minute but does not alter how incidents are created from the alerts it generates. NRT rules still produce one incident per alert unless you explicitly configure incident grouping elsewhere, and NRT rules have limited grouping capabilities compared to scheduled rules. Therefore, switching to NRT neither groups incidents nor prevents a new incident from being created each time the rule triggers.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.