mediumMultiple Choice
SC-200 Practice Question: A SOC analyst in Microsoft Sentinel is creating a…
A SOC analyst in Microsoft Sentinel is creating a scheduled analytics rule to detect anomalous Microsoft Entra ID sign-ins. The rule runs every 5 minutes and queries the SigninLogs table for sign-ins from IP addresses outside the organization's known country codes. To avoid duplicates, the rule should generate an incident only once for a particular user-IP combination until the combination is not seen for 60 minutes. Which configuration should the analyst use in the analytics rule wizard?
⚠ Common exam trap
Many exam-takers confuse the Query scheduling section's 'Run query every' and 'Lookup data from the last' settings with deduplication, not realizing that those control query frequency and data range, not incident grouping or suppression based on entity combinations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident settings tab - Grouping configuration
The Incident settings tab's Grouping configuration allows you to group alerts into a single incident based on specific criteria, such as user-IP combination, and to suppress re-creation of an incident for a defined time window (e.g., 60 minutes) after the last occurrence. This directly addresses the requirement to avoid duplicate incidents for the same user-IP pair until it is not seen for 60 minutes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Alert details section
Why it's wrong here
The Alert details section defines how the alert is displayed, including its name, description, severity, and MITRE tactics, but it has no bearing on how Sentinel decides whether separate alert occurrences constitute the same incident. These fields are purely informational and cosmetic for the analyst. Duplicate prevention is solely controlled by the incident creation settings, specifically the grouping configuration in the Incident settings tab, which aggregates related alerts into one incident.
- ✗
Query scheduling section
Why it's wrong here
Query scheduling controls the rule's execution frequency and the data lookback window for the query, determining how often the rule runs and which events are evaluated. While run frequency can influence the volume of alerts generated, it does not merge or suppress duplicate alerts into a single incident. The grouping window, configured separately in the Incident settings tab, defines the time frame during which alerts are combined and when that grouping window resets to avoid duplicate incidents.
- ✓
Incident settings tab - Grouping configuration
Why this is correct
The Incident settings tab contains the grouping configuration, which allows you to enable incident grouping and set a grouping window during which alerts triggered by the same rule are automatically merged into a single incident. Crucially, you can enable 'Reset grouping' to restart the grouping window whenever certain properties change, such as a new entity being found, thereby preventing duplicate incidents by beginning a fresh aggregation period. This is the exact mechanism that addresses the creation of duplicate incidents for repeated events within a short timeframe.
- ✗
Entity mapping section
Why it's wrong here
Entity mapping links fields from the query output to recognized entity types like accounts, hosts, and IP addresses, enriching alerts with contextual information for investigation and advanced hunting. However, it only associates entities with alerts; it does not influence the incident creation logic or deduplicate alerts. The decision to group alerts into an incident and prevent duplicates is made exclusively by the incident settings grouping configuration, not by entity mapping.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.