SC-100 Design security solutions for infrastructure Practice Question
Your company plans to use Microsoft Sentinel to manage security incidents. You need to design a solution that reduces alert fatigue by grouping related alerts into incidents. Which feature should you enable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analytics rule with alert grouping enabled
The correct option is A, an analytics rule with alert grouping enabled, because in Microsoft Sentinel analytics rules can be configured with incident grouping so that related alerts are consolidated into a single incident, directly reducing alert fatigue. Grouping settings let you combine alerts that share entities or occur within a defined timeframe, which is exactly the scenario's requirement. Watchlists (B) are for storing reference data used in queries and detections, not for grouping alerts into incidents. Automation rules (C) and playbooks (D) respond to or orchestrate actions on alerts/incidents but do not themselves group related alerts into incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Analytics rule with alert grouping enabled
Why this is correct
The correct mechanism for grouping related alerts into a single incident is configuring an analytics rule with alert grouping enabled. When enabled, the rule's alert grouping settings (such as grouping by entities or within a defined time window) cause multiple qualifying alerts to be automatically combined into one incident, rather than each alert creating a separate incident. This reduces alert noise and gives security analysts a correlated view of a potential attack chain.
- ✗
Watchlists to filter noisy alerts
Why it's wrong here
Watchlists are lookup tables used for filtering, enriching, or correlating data within analytics rules, not for grouping alerts into incidents. They can help suppress noisy alerts by excluding or prioritizing matching data before rule logic runs, but they do not alter how multiple alerts are aggregated into incidents. Watchlists operate at the query stage, whereas alert grouping is a post-query incident-creation behavior.
- ✗
Automation rules that trigger on alert creation
Why it's wrong here
Automation rules that trigger on alert creation execute actions like adding tags, assigning severity, or running playbooks, but they cannot merge separate alerts into a single incident. They act on each alert individually as it is generated, and they do not have a mechanism to retrospectively combine multiple alerts that were already processed by analytics rules. Their purpose is to automate responses, not to define incident aggregation.
- ✗
Playbooks that run on alert creation
Why it's wrong here
Playbooks that run on alert creation automate response actions (e.g., opening a ticket, sending email) after an alert is generated, but they lack the ability to group multiple alerts into one incident. Playbooks are invoked per alert or per incident, and their response actions cannot modify the incident generation pipeline or consolidate alerts. They are purely reactive, not a grouping or aggregation function.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.