mediumMultiple Choice
SC-200 Practice Question: A SOC analyst wants to ensure that multiple…
A SOC analyst wants to ensure that multiple alerts from the same analytics rule that occur within a 1-hour window for the same user are automatically merged into a single incident. Which configuration setting should the analyst adjust in the analytics rule?
⚠ Common exam trap
Watch out — candidates often confuse Entity mapping with incident grouping, thinking that mapping entities automatically merges alerts, but entity mapping only enriches alerts with contextual data and does not control grouping logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident grouping settings
The Incident grouping settings in a Microsoft Sentinel analytics rule control whether multiple alerts from the same rule are automatically merged into a single incident. By configuring the grouping to 'Group alerts into a single incident if they match the specified conditions' and setting the time window to 1 hour, the SOC analyst ensures that alerts triggered for the same user within that window are combined, reducing alert noise and improving incident management efficiency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incident grouping settings
Why this is correct
Incident grouping settings directly control whether and how multiple alerts are consolidated into a single incident. In an analytics rule's Incident creation section, you can enable alert grouping and specify a time window (up to 24 hours) as well as select entity types or alert attributes to match on. By adjusting these settings—for instance, grouping by user or host—the SOC analyst ensures that alerts from the same entity or timeframe automatically roll up into one incident rather than generating separate ones.
- ✗
Entity mapping
Why it's wrong here
Entity mapping defines which alert properties are extracted as entities such as user, IP address, URL, or host, and it provides context for investigation. While incident grouping can use entity matches as a grouping criterion, the mapping itself does not perform grouping logic. Changing entity mappings only affects how entities are displayed or linked, not whether alerts become part of the same incident, so it cannot be used to consolidate alerts.
- ✗
Alert details
Why it's wrong here
Alert details is a configuration section in an analytics rule that allows customizing fields like Alert Name, Severity, Description, or adding key-value pairs for more context. It does not influence incident creation or aggregation behavior. Even if you modify alert details, each matching query still produces its own alert independently, and the grouping of those alerts remains a function of incident grouping settings, making this option ineffective for the analyst's goal.
- ✗
Query scheduling
Why it's wrong here
Query scheduling sets how often a scheduled analytics rule runs and the start/end time window it looks back over (e.g., every 5 minutes with a 10-minute lookback). This affects how frequently alerts are created and what data is examined, but it has no bearing on how multiple alerts are merged into incidents. Two alerts from the same entity generated in the same run or different runs will be grouped solely based on the incident grouping configuration, not on the schedule, so increasing or lowering frequency does not consolidate alerts.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.