Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "incidentConfiguration": {
      "createIncident": true,
      "groupingConfiguration": {
        "enabled": false,
        "reopenClosedIncident": false,
        "lookbackDuration": "PT5M"
      }
    }
  }
}
```

Refer to the exhibit. You are configuring a Microsoft Sentinel scheduled analytics rule with the above incident creation settings. What is the effect of setting 'groupingConfiguration.enabled' to false?

⚠ Common exam trap

SC-200 often tests the distinction between alert grouping, alert suppression, and rule frequency, causing candidates to confuse groupingConfiguration.enabled with suppression or scheduling settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Each alert will generate a separate incident

When groupingConfiguration.enabled is set to false in a Microsoft Sentinel scheduled analytics rule, the alert-grouping logic is disabled entirely. This means Sentinel will not bundle multiple alerts from a single rule run into one incident; instead, every individual alert generated by the query produces its own distinct incident. This is useful when each alert requires separate triage or when alerts represent unrelated events that should not be merged.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Alerts will be suppressed for 5 minutes

    Why it's wrong here

    Alert suppression is governed by the rule's suppression settings, not groupingConfiguration, which controls whether alerts merge into a single incident. Turning grouping off yields one incident per alert; suppression would be the correct control when the aim is to mute repeated alerts for a period.

  • ✗

    The rule will run every 5 minutes

    Why it's wrong here

    Rule execution frequency is set by the query scheduling (run every X minutes) in the rule definition, independent of groupingConfiguration. Grouping only governs how alerts combine into incidents; the schedule would be the correct setting to alter when changing how often the rule runs.

  • ✗

    No incidents will be created

    Why it's wrong here

    Disabling groupingConfiguration does not stop incident creation; it makes Sentinel raise a separate incident for every matching alert rather than merging them into one. Grouping is the mechanism that consolidates related alerts, so its removal changes incident count, not whether incidents exist.

  • ✓

    Each alert will generate a separate incident

    Why this is correct

    With groupingConfiguration.enabled set to false, Sentinel disables alert grouping, so each individual alert raised by the rule creates its own incident rather than being merged into a single incident. This satisfies the scenario's requirement for one incident per alert.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.