Courseiva
hardMultiple Select

SC-200 Practice Question: A Microsoft Sentinel scheduled analytics rule…

A Microsoft Sentinel scheduled analytics rule detects impossible travel but creates too many duplicate incidents for the same user within a short period. Which two rule settings should you tune? (Choose 2.)

⚠ Common exam trap

Many candidates confuse suppression (which stops alert creation) with incident grouping (which consolidates alerts into incidents), and may incorrectly think disabling the data connector or deleting the workspace are valid tuning actions for reducing duplicates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure event grouping or incident grouping by user entity.

Configuring event grouping or incident grouping by user entity consolidates multiple alerts for the same user into a single incident, reducing duplicate incidents. In Microsoft Sentinel, this setting controls how alerts are aggregated into incidents based on entity fields like user account, ensuring that a burst of impossible travel alerts for the same user generates one incident instead of many.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure event grouping or incident grouping by user entity.

    Why this is correct

    In the scheduled analytics rule's "Alert grouping" and "Event grouping" settings, you can define that query results containing the same user entity are combined into a single alert, and later that multiple alerts referencing the same user are combined into one incident. This consolidation directly addresses alert fatigue by collapsing many impossible-travel event pairs into one investigation object centered on the affected user. However, you must consider grouping by other entities like location or IP to avoid over-consolidating distinct attacker activities.

  • ✓

    Configure suppression to stop creating new alerts for a defined period after a match.

    Why this is correct

    The rule's "Suppression" setting stops the scheduled query from executing for a defined duration after an alert is generated, preventing the same condition from creating duplicate alerts. While this is an effective way to reduce repeated notifications from a persistent impossible-travel pattern, it is less precise than entity grouping because it completely blinds the rule—even if a new, legitimate sign-in anomaly occurs during the suppression window, no alert will be created. Therefore, suppression should be configured with an appropriate period based on how quickly the SOC expects to investigate.

  • ✗

    Disable the data connector.

    Why it's wrong here

    Disabling the data connector—for instance, the sign-in logs connector—simply halts ingestion of the telemetry the impossible-travel rule depends on. The rule will stop firing because the underlying data never reaches the Log Analytics workspace, but this also breaks every other analytics rule and investigation that relies on those logs, such as risky sign-in and other identity threats. This is not a targeted tuning action; it destroys visibility rather than reducing redundant alerts.

  • ✗

    Delete the Log Analytics workspace.

    Why it's wrong here

    Deleting the Log Analytics workspace is a destructive, irreversible action that removes the entire Microsoft Sentinel environment, including the analytics rule, all stored log data, workbooks, and playbooks. This is never an acceptable remediation for alert duplication—it would eliminate the SOC's ability to investigate any incidents, not just impossible travel. Additionally, due to data retention and cost implications, this action should be considered a last-resort decommissioning step, not a rule-tuning option.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.