SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit.
```json
{
"properties": {
"displayName": "Ransomware Detection",
"description": "Detects ransomware patterns",
"severity": "High",
"enabled": true,
"query": "SecurityAlert | where AlertName contains \"Ransomware\"",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0,
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"reopenClosedIncident": false,
"lookbackDuration": "PT5H",
"entitiesMatchingMethod": "All"
}
}
}
}
```Refer to the exhibit. You are reviewing a Microsoft Sentinel analytics rule created via ARM template. What is the effect of the grouping configuration?
⚠ Common exam trap
A common mix-up: candidates confuse the grouping lookback window with alert suppression or mistaking 'any entity matches' for 'all entities match,' which leads candidates to pick Option A or C instead of D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Groups alerts into one incident if all entities match within a 5-hour lookback.
The grouping configuration in the exhibit sets the grouping condition to 'Group alerts into a single incident if all entities match' with a 5-hour lookback period. This means that alerts generated within 5 hours that share identical entities (e.g., same IP, host, or account) will be merged into one incident, reducing alert noise. Option D correctly describes this behavior, as it specifies both the entity matching requirement and the time window.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Groups alerts into one incident if any entity matches.
Why it's wrong here
The incident creation rule specifies entitiesMatchingMethod as All, not Any. With All, every entity in the alert must match the corresponding entities of a previous alert within the lookback window for the alerts to be grouped. Choosing Any would group alerts that share only one entity, which can incorrectly merge unrelated events that happen to involve a common IP or user.
- ✗
Creates a separate incident for each alert.
Why it's wrong here
This is wrong because the configuration has groupingEnabled set to true, meaning alerts are intentionally consolidated into incidents rather than each alert becoming its own incident. If separate incidents per alert were desired, grouping would be disabled and each alert would generate a unique incident. The presence of a 5-hour lookback and entity matching rules shows that alert grouping into a single incident is active here.
- ✗
Suppresses alerts for 5 hours after the first alert.
Why it's wrong here
Incorrect: suppression is disabled (suppressionEnabled: false), so no alert suppression is occurring. The 5-hour window is the lookback duration used for grouping alerts based on matching entities, not a suppression period. Suppression would instead prevent new incidents for the same type of alert after an incident is resolved, which is not how this rule is configured.
- ✓
Groups alerts into one incident if all entities match within a 5-hour lookback.
Why this is correct
This is correct because the rule groups alerts into a single incident when all entities match within the 5-hour lookback. The entitiesMatchingMethod is All, and lookbackDuration is 5 hours, so only alerts that share every entity value (such as account, host, and IP) in that window will be merged. This consolidates related alerts while minimizing the chance of grouping unrelated activity, and the same incident can be reopened or updated as more matching alerts arrive.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are reviewing an analytics rule configuration in Microsoft Sentinel using ARM template JSON. The rule is enabled and incident creation is set to true. However, when alerts are generated, they are not being grouped into a single incident. What is the most likely reason?
hard- A.The lookbackDuration is set to 5 hours which is too short.
- ✓ B.The groupingConfiguration is disabled.
- C.The matchingMethod is set to 'AllEntities' which is not supported.
- D.The rule is not enabled properly.
Why B: The groupingConfiguration in Microsoft Sentinel analytics rules controls whether alerts are grouped into a single incident. When this configuration is disabled, each alert generates its own separate incident, even if the rule is enabled and incident creation is set to true. Therefore, the most likely reason alerts are not being grouped is that the groupingConfiguration is disabled.
Variation 2. Your organization uses Microsoft Sentinel. You have a custom analytics rule that generates incidents based on a KQL query. The rule is configured to run every 5 minutes. You notice that the rule is generating duplicate incidents for the same event. What should you do to prevent duplicates?
hard- A.Create an automation rule that deletes duplicate incidents.
- B.Set the rule to group alerts into a single incident if they occur within 5 minutes.
- C.Create a playbook that checks for duplicates before incident creation.
- ✓ D.Enable entity mapping in the analytics rule and set appropriate entities.
Why D: Duplicate incidents in Microsoft Sentinel typically occur when the analytics rule cannot correlate alerts to the same underlying entity, so each run treats the event as new. Enabling entity mapping (Account, Host, IP, etc.) lets Sentinel recognize that alerts share the same entities and group them into a single incident rather than creating separate ones. This is the built-in mechanism for deduplication and incident correlation.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.