Courseiva
mediumMultiple Choice

SC-200 Practice Question: A SOC analyst wants to ensure that multiple…

A SOC analyst wants to ensure that multiple alerts from the same analytics rule that occur within a 1-hour window for the same user are automatically merged into a single incident. Which configuration setting should the analyst adjust in the analytics rule?

⚠ Common exam trap

Watch out — candidates often confuse Entity mapping with incident grouping, thinking that mapping entities automatically merges alerts, but entity mapping only enriches alerts with contextual data and does not control grouping logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incident grouping settings

The Incident grouping settings in a Microsoft Sentinel analytics rule control whether multiple alerts from the same rule are automatically merged into a single incident. By configuring the grouping to 'Group alerts into a single incident if they match the specified conditions' and setting the time window to 1 hour, the SOC analyst ensures that alerts triggered for the same user within that window are combined, reducing alert noise and improving incident management efficiency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Incident grouping settings

    Why this is correct

    Incident grouping settings directly control whether and how multiple alerts are consolidated into a single incident. In an analytics rule's Incident creation section, you can enable alert grouping and specify a time window (up to 24 hours) as well as select entity types or alert attributes to match on. By adjusting these settings—for instance, grouping by user or host—the SOC analyst ensures that alerts from the same entity or timeframe automatically roll up into one incident rather than generating separate ones.

  • ✗

    Entity mapping

    Why it's wrong here

    Entity mapping defines which alert properties are extracted as entities such as user, IP address, URL, or host, and it provides context for investigation. While incident grouping can use entity matches as a grouping criterion, the mapping itself does not perform grouping logic. Changing entity mappings only affects how entities are displayed or linked, not whether alerts become part of the same incident, so it cannot be used to consolidate alerts.

  • ✗

    Alert details

    Why it's wrong here

    Alert details is a configuration section in an analytics rule that allows customizing fields like Alert Name, Severity, Description, or adding key-value pairs for more context. It does not influence incident creation or aggregation behavior. Even if you modify alert details, each matching query still produces its own alert independently, and the grouping of those alerts remains a function of incident grouping settings, making this option ineffective for the analyst's goal.

  • ✗

    Query scheduling

    Why it's wrong here

    Query scheduling sets how often a scheduled analytics rule runs and the start/end time window it looks back over (e.g., every 5 minutes with a 10-minute lookback). This affects how frequently alerts are created and what data is examined, but it has no bearing on how multiple alerts are merged into incidents. Two alerts from the same entity generated in the same run or different runs will be grouped solely based on the incident grouping configuration, not on the schedule, so increasing or lowering frequency does not consolidate alerts.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.