Courseiva

SC-200 Manage a security operations environment Practice Question

You are a SOC analyst using Microsoft Sentinel. You have a scheduled analytics rule that generates incidents from KQL queries. Recently, incidents are being created but automatically closed within minutes without any actions taken. You suspect a configuration issue. What should you check first?

⚠ Common exam trap

Many candidates confuse 'suppression' (which stops alert creation) with 'automation rules' (which can close incidents), leading them to choose Option B instead of recognizing that suppression does not affect existing incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the incident automation rules that might have a 'Close incident' action triggered by a condition.

Incident automation rules in Microsoft Sentinel can be configured to automatically close incidents when specific conditions are met, such as a related alert being resolved or a playbook completing. Since the incidents are being closed within minutes without manual intervention, an automation rule with a 'Close incident' action is the most likely cause, as it directly triggers closure based on conditions. Checking this first aligns with the SOC analyst's need to identify automated actions that could prematurely close incidents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Verify the 'Alert grouping' settings in the analytics rule; they might be grouping alerts incorrectly.

    Why it's wrong here

    Alert grouping in an analytics rule consolidates multiple alerts into a single incident based on time windows and entity matching. While misconfiguration can cause unrelated alerts to be merged into one incident, grouping does not alter the incident's lifecycle or status. Automatic closure of an incident is only possible through an automation rule or playbook that explicitly executes a 'Close incident' action, so adjusting grouping settings would not address the unexpected closure.

  • ✗

    Check if the analytics rule has a 'Suppression' setting enabled that causes the incident to close.

    Why it's wrong here

    The 'Suppression' setting on an analytics rule temporarily disables alert generation for a specified duration after a qualifying alert is created. This mechanism prevents new alerts from being generated, but it does not modify any already-created incidents, including their status or closure state. Since suppression does not invoke a workflow that changes incident status, it cannot cause an incident to close automatically.

  • ✓

    Review the incident automation rules that might have a 'Close incident' action triggered by a condition.

    Why this is correct

    Incident automation rules in Microsoft Sentinel run automatically upon incident creation or update, and they can include a 'Close incident' action when defined conditions are met. For example, a rule with a condition like 'Alert severity equals Low' will close any newly created matching incident without human intervention. Reviewing these rules is the correct approach because they are the primary native mechanism that automatically closes incidents based on incident properties.

  • ✗

    Examine the entity mapping configuration; it might be causing the incident to close automatically.

    Why it's wrong here

    Entity mapping in an analytics rule enriches incidents by associating entities such as accounts, hosts, or IP addresses extracted from alert data. This enhancement is used for investigation and advanced hunting, but it does not execute any automation workflow or change the incident's status. Automatic closure of an incident relies on automation rules or playbooks that explicitly issue a 'Close incident' command, so examining entity mapping cannot reveal the reason for the closure.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.