Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "incidentConfiguration": {
      "createIncident": true,
      "groupingConfiguration": {
        "enabled": true,
        "reopenClosedIncident": false,
        "lookbackDuration": "PT5H",
        "matchingMethod": "AllEntities",
        "groupByEntities": [],
        "groupByAlertDetails": [],
        "groupByCustomDetails": null
      }
    },
    "alertRuleTemplateName": null,
    "description": "Detects suspicious sign-ins.",
    "displayName": "Suspicious Sign-In",
    "enabled": true,
    "query": "SigninLogs | where ResultType == 50057"
  }
}
```

Refer to the exhibit. You are reviewing a Microsoft Sentinel scheduled analytics rule configured as above. An incident was created for multiple alerts triggering within a 5-hour window. The SOC team needs to investigate each alert separately because they involve different user accounts. What should the analyst do to ensure each alert generates a separate incident?

⚠ Common exam trap

Many exam-takers confuse disabling grouping with changing the matchingMethod or lookbackDuration, thinking those options separate alerts, when in fact only setting 'enabled' to false under groupingConfiguration achieves true per-alert incident creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set 'enabled' to false under groupingConfiguration.

Setting 'enabled' to false under groupingConfiguration disables alert grouping entirely. When grouping is disabled, each individual alert that triggers the scheduled rule will generate its own separate incident, allowing the SOC team to investigate alerts involving different user accounts independently.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the matchingMethod to 'AnyAlert'.

    Why it's wrong here

    AnyAlert is a valid matchingMethod value in the groupingConfiguration, but it instructs Sentinel to combine every alert that occurs within the lookbackDuration into one incident regardless of entity similarity. This is the opposite of reducing grouping and would make the SOC even more likely to see a single incident containing many unrelated alerts. Because the objective is to prevent alerts from being grouped together, AnyAlert fails to meet the requirement.

  • ✓

    Set 'enabled' to false under groupingConfiguration.

    Why this is correct

    Setting enabled to false under groupingConfiguration completely disables the alert grouping engine for that analytics rule. With grouping disabled, Sentinel no longer applies entity-matching or lookback logic, and each individual alert will generate its own independent incident. This is the only direct way to guarantee a one-to-one mapping from alert to incident, which is exactly the desired behavior.

  • ✗

    Set 'reopenClosedIncident' to true.

    Why it's wrong here

    The reopenClosedIncident property controls what happens when a new alert fires and a matching incident has already been closed, not whether alerts are combined when the incident is first created. Setting it to true would cause Sentinel to reopen a closed incident that matches the grouping criteria, but that presupposes grouping is still active and that the alert has been assigned to that existing incident. It does nothing to stop multiple alerts from being bundled into the same incident during the original grouping pass.

  • ✗

    Change the lookbackDuration to PT0H.

    Why it's wrong here

    Changing lookbackDuration to PT0H does not disable grouping, it only narrows the time window within which alerts are evaluated for consolidation. Even with a zero-second lookback, Sentinel can still group alerts that share the exact same occurrence timestamp or that arrive in the same processing batch because the groupingConfiguration remains enabled. To achieve one incident per alert, you must disable grouping itself rather than simply shrinking the lookback window.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.