SC-200 Manage a security operations environment Practice Question
Which TWO features in Microsoft Sentinel can help reduce alert fatigue by grouping related alerts into incidents? (Select two.)
⚠ Common exam trap
A common mix-up: candidates confuse 'automation rules' (which automate responses) with 'incident creation' (which groups alerts), or they mistakenly think entity behavior analytics or threat intelligence indicators perform the grouping function, when in fact only incident merging and analytics rules with incident creation settings can consolidate related alerts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident merging
Incident merging (Option A) is correct because it automatically combines multiple alerts that share common entities (such as IP addresses, hostnames, or user accounts) into a single incident. This reduces alert fatigue by preventing security analysts from having to triage dozens of separate alerts that are all part of the same attack chain, allowing them to focus on a single, consolidated incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incident merging
Why this is correct
Incident merging in Microsoft Sentinel combines multiple incidents that are part of the same attack campaign or share entities into a single incident. This directly reduces the number of incidents analysts must triage, lowering mean time to respond and preventing alert fatigue. By minimizing the chance that a critical alert is lost in a queue, it reduces the financial impact of a successful breach, thus lowering annualized loss expectancy.
- ✗
Entity behavior analytics
Why it's wrong here
Entity behavior analytics (UEBA) profiles entities and flags anomalies by comparing activity against historical baselines. While it provides valuable detection and investigation context, it does not group or consolidate related alerts into fewer incidents—in fact, it can generate additional independent alerts. Since it does not reduce the total incident volume and may even increase noise, it does not help reduce ALE in the expected way.
- ✗
Automation rules that run playbooks
Why it's wrong here
Automation rules that run playbooks execute predefined response actions after an incident has been created, such as sending notifications, creating tickets, or running remediation steps. They are valuable for speeding up response and ensuring consistency, but they operate on incidents that already exist rather than combining or preventing them. Because they do not reduce the number of incidents in the queue, they are not the feature that primarily reduces ALE.
- ✓
Analytics rules that create incidents
Why this is correct
Analytics rules can be configured with alert grouping settings that group multiple alerts matching the same entity or within a defined time window into a single incident. This consolidation means that rather than creating dozens of separate incidents, the rule produces one focused incident for the entire attack chain. By lowering the number of incidents and helping analysts focus on the broader attack, the rule reduces workload and response time, thereby reducing ALE.
- ✗
Threat intelligence indicators
Why it's wrong here
Threat intelligence indicators provide lists of known malicious IPs, domains, URLs, and file hashes that Sentinel can match against for detection and enrichment. These indicators give context and can trigger analytics rules, but they do not group or deduplicate related alerts and incidents. In practice, aggressive matching can generate a high volume of alerts, which increases noise and incident count rather than reducing it, so it does not directly lower ALE.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.