SC-200 Manage a security operations environment Practice Question
You are configuring a Microsoft Sentinel analytics rule to detect failed logons from multiple IP addresses. The rule should trigger an incident only when the same user account has failed logons from more than three distinct IP addresses within 5 minutes. Which rule setting should you configure?
⚠ Common exam trap
Many candidates confuse 'Group by' (which splits alerts by field values) with the ability to count distinct values across those groups, leading them to select Option B instead of recognizing that a custom threshold on distinct count is required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the 'Alert threshold' to 'Custom' and define a condition on distinct IP count.
The requirement is to trigger an incident only when the same user account has failed logons from more than three distinct IP addresses within 5 minutes. In Microsoft Sentinel analytics rules, the 'Alert threshold' set to 'Custom' allows you to define a condition on the count of distinct values (e.g., distinct IP addresses) aggregated over the rule's query window, which directly matches the scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set the 'Alert threshold' to 'Custom' and define a condition on distinct IP count.
Why this is correct
Setting the Alert threshold to Custom lets you specify an aggregation condition on the query results, such as dcount(IP_Address) greater than a numeric value. This matches the required detection of a single account being accessed from many distinct IPs, which indicates distributed brute-force activity. The rule will fire only when the distinct IP count crosses the defined threshold.
- ✗
Set the 'Group by' field to 'Account' and 'IP address'.
Why it's wrong here
Configuring Group by with Account and IP address merely tells the rule how to bucket query results for aggregation, but it does not introduce any threshold itself. Even with grouping, every event or group could still generate an alert unless a separate condition is defined. It also may fragment the alert into per-account-per-IP buckets, potentially hiding the overall distinct IP count across a single account.
- ✗
Set the 'Event grouping' to 'Group all events into a single alert'.
Why it's wrong here
Event grouping set to 'Group all events into a single alert' only collapses all matching events from the query window into one alert record, avoiding alert flooding. It has no effect on the underlying detection logic, so it cannot enforce a condition on the number of distinct IP addresses. Without a custom threshold, a single event or many events will still trigger a single alert equally, so this does not satisfy the requirement.
- ✗
Set the 'Suppression' to '5 minutes' after an alert is generated.
Why it's wrong here
Suppression for 5 minutes after an alert is generated temporarily pauses the rule's production of subsequent alerts for the same rule instance, which is intended to reduce duplicate notifications. It occurs after the alert has already been created, so it cannot prevent an alert from being generated when the distinct IP count is too low. Since the trigger condition is evaluated before suppression is applied, this setting is irrelevant to detecting a threshold on distinct IP count.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.