SC-200 Respond to security incidents Practice Question
Exhibit
Refer to the exhibit.
```json
{
"properties": {
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": false,
"reopenClosedIncident": false,
"lookbackDuration": "PT5M"
}
}
}
}
```Refer to the exhibit. You are configuring a Microsoft Sentinel scheduled analytics rule with the above incident creation settings. What is the effect of setting 'groupingConfiguration.enabled' to false?
⚠ Common exam trap
SC-200 often tests the distinction between alert grouping, alert suppression, and rule frequency, causing candidates to confuse groupingConfiguration.enabled with suppression or scheduling settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Each alert will generate a separate incident
When groupingConfiguration.enabled is set to false in a Microsoft Sentinel scheduled analytics rule, the alert-grouping logic is disabled entirely. This means Sentinel will not bundle multiple alerts from a single rule run into one incident; instead, every individual alert generated by the query produces its own distinct incident. This is useful when each alert requires separate triage or when alerts represent unrelated events that should not be merged.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Alerts will be suppressed for 5 minutes
Why it's wrong here
Alert suppression is governed by the rule's suppression settings, not groupingConfiguration, which controls whether alerts merge into a single incident. Turning grouping off yields one incident per alert; suppression would be the correct control when the aim is to mute repeated alerts for a period.
- ✗
The rule will run every 5 minutes
Why it's wrong here
Rule execution frequency is set by the query scheduling (run every X minutes) in the rule definition, independent of groupingConfiguration. Grouping only governs how alerts combine into incidents; the schedule would be the correct setting to alter when changing how often the rule runs.
- ✗
No incidents will be created
Why it's wrong here
Disabling groupingConfiguration does not stop incident creation; it makes Sentinel raise a separate incident for every matching alert rather than merging them into one. Grouping is the mechanism that consolidates related alerts, so its removal changes incident count, not whether incidents exist.
- ✓
Each alert will generate a separate incident
Why this is correct
With groupingConfiguration.enabled set to false, Sentinel disables alert grouping, so each individual alert raised by the rule creates its own incident rather than being merged into a single incident. This satisfies the scenario's requirement for one incident per alert.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.