Courseiva

SC-200 Respond to security incidents Practice Question

You are investigating a ransomware incident in Microsoft Sentinel. The incident contains multiple alerts. You need to group related alerts under the same incident to reduce alert fatigue. What should you do?

⚠ Common exam trap

Test-takers frequently confuse automation rules (which handle incident actions) with incident creation settings within analytics rules, mistakenly thinking automation rules can merge incidents when they cannot.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure incident creation rules in the analytics rule.

In Microsoft Sentinel, incident creation is configured directly within the analytics rule. When you create or edit an analytics rule, the 'Incident creation' settings allow you to enable incident generation from alerts triggered by that rule. This ensures that all alerts from the same rule are grouped into a single incident, reducing alert fatigue by preventing multiple separate incidents for related alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable User and Entity Behavior Analytics (UEBA).

    Why it's wrong here

    Enabling User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel provides behavioral baselines and anomaly detection for entities like users and hosts, but it does not aggregate or correlate alerts into incidents. UEBA enriches alerts with additional context rather than changing how alerts are grouped or merged. Since the requirement is to combine multiple alerts into a single incident, UEBA alone cannot accomplish this.

  • ✗

    Create a new analytics rule to combine alerts.

    Why it's wrong here

    Creating a new analytics rule that attempts to combine alerts is conceptually invalid in Microsoft Sentinel because analytics rules are scheduled or event-driven queries that generate alerts from raw data; they do not consume existing alerts as their input. Alert aggregation is a capability of the incident-creation configuration within each analytics rule, not a separate rule that operates on already-generated alerts. A new analytics rule would produce additional alerts rather than merging the existing ones into a incident.

  • ✗

    Use an automation rule to merge incidents.

    Why it's wrong here

    Automation rules in Microsoft Sentinel automate responses to incidents—such as changing status, assigning owners, adding tags, or running playbooks—but they cannot merge incidents. There is no action or trigger in automation rules that supports combining two or more incidents into a single entity. Incident merging is not a supported Sentinel operation; the correct method is to group alerts at the source by configuring incident creation in the analytics rule.

  • ✓

    Configure incident creation rules in the analytics rule.

    Why this is correct

    Configuring incident creation rules in the analytics rule is the correct way to combine related alerts into a single incident in Microsoft Sentinel. When editing an analytics rule, you can enable incident creation and set alert grouping to group up to 150 alerts into one incident based on matching entities (such as account or host) within a defined time window (up to 24 hours). This approach ensures that alerts from the same attack campaign are represented as a single incident, reducing alert fatigue and providing a unified scope for investigation.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.