Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

{"type": "Microsoft.SecurityInsights/alertRules", "apiVersion": "2023-02-01-preview", "properties": { "displayName": "MFA Disabled", "query": "IdentityInfo | where Timestamp > ago(5h) | where IsMfaRegistered == false", "triggerOperator": "gt", "triggerThreshold": 0, "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "incidentConfiguration": { "createIncident": true, "groupingConfiguration": { "enabled": false } } } }

Refer to the exhibit. You are reviewing an Azure Resource Manager (ARM) template for a Microsoft Sentinel analytics rule. Based on the exhibit, which statement is true?

⚠ Common exam trap

Test-takers frequently confuse the 'frequency' and 'period' values (both PT5H) with a common 1-hour interval, or misinterpret 'AlertPerResult' as grouping alerts into incidents, when in fact it creates one alert per query result row.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The rule will generate one alert per user that has MFA disabled.

The ARM template configures a Microsoft Sentinel scheduled analytics rule that runs every hour, queries for users with MFA disabled, and uses the 'Alert Per Result' event grouping setting. This setting generates a separate alert for each unique result returned by the query, meaning each user who has MFA disabled triggers its own alert.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The rule will create one incident per alert and group alerts by entity.

    Why it's wrong here

    The incident creation/grouping section of the rule controls whether multiple alerts are consolidated into one incident. When alert grouping is disabled—as the exhibit shows—alerts are not grouped by entity; instead, every alert produces its own incident. Since this rule uses Alert Per Result, each user with MFA disabled yields an alert, and each alert becomes a separate incident, not a grouped one.

  • ✗

    The rule will only trigger if more than 5 users have MFA disabled.

    Why it's wrong here

    This option is false because the alert threshold is defined by the 'Number of results' condition, which is set to 'greater than 0' (the default in Microsoft Sentinel). That means the rule triggers whenever the query returns any matching user, not only when more than five users are returned. The query filters for users with MFA disabled, but there is no five-user threshold configured in the analytics rule.

  • ✗

    The rule runs every hour and looks back 5 hours.

    Why it's wrong here

    The query period (look-back) is five hours, meaning the rule evaluates data from the last five hours in each run. However, the frequency—how often the rule executes—is not visible in the snippet shown in the exhibit and defaults to five hours in Microsoft Sentinel when not specified, not one hour. Therefore, you cannot conclude that the rule runs every hour; the actual schedule may be five hours or a custom value.

  • ✓

    The rule will generate one alert per user that has MFA disabled.

    Why this is correct

    This is correct because the analytics rule is configured with 'Alert Per Result,' which instructs Microsoft Sentinel to create an independent alert for every row returned by the query. The query returns one row for each user who has MFA disabled, so each of those users triggers a separate alert. No incident grouping is applied, so each of these alerts is also converted into its own incident.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.