Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "incidentConfiguration": {
      "createIncident": true,
      "groupingConfiguration": {
        "enabled": false,
        "reopenClosedIncident": false,
        "lookbackDuration": "PT5H",
        "matchingMethod": "AllEntities",
        "groupByEntities": [],
        "groupByAlertDetails": [],
        "groupByCustomDetails": []
      }
    },
    "alertRuleTemplateName": "Template101",
    "enabled": true,
    "displayName": "Test Rule"
  }
}
```

You are reviewing an analytics rule configuration in Microsoft Sentinel using ARM template JSON. The rule is enabled and incident creation is set to true. However, when alerts are generated, they are not being grouped into a single incident. What is the most likely reason?

⚠ Common exam trap

The trap here is that candidates often focus on the lookbackDuration or matchingMethod as the cause of grouping failure, overlooking that the groupingConfiguration must be explicitly enabled for any grouping to occur.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The groupingConfiguration is disabled.

The groupingConfiguration in Microsoft Sentinel analytics rules controls whether alerts are grouped into a single incident. When this configuration is disabled, each alert generates its own separate incident, even if the rule is enabled and incident creation is set to true. Therefore, the most likely reason alerts are not being grouped is that the groupingConfiguration is disabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The lookbackDuration is set to 5 hours which is too short.

    Why it's wrong here

    The lookbackDuration is only evaluated when groupingConfiguration is enabled, and this rule has grouping disabled. Because no grouping occurs, the 5-hour lookback value is ignored entirely; there is no 'too short' or 'too long' setting that affects alert-to-incident creation under this configuration. Even if the lookback were extended, each alert would still open its own incident.

  • ✓

    The groupingConfiguration is disabled.

    Why this is correct

    With groupingConfiguration disabled, every alert that the rule generates is immediately converted into its own individual incident. This is exactly why you are seeing separate incidents despite alerts sharing common entities or firing within the same time window. To combine related alerts, grouping must be enabled and configured with a matching method and appropriate lookbackDuration.

  • ✗

    The matchingMethod is set to 'AllEntities' which is not supported.

    Why it's wrong here

    AllEntities is a valid matchingMethod value in Sentinel's groupingConfiguration, so this is not an unsupported setting. However, the method only takes effect when grouping is enabled; since groupingConfiguration is disabled, matchingMethod is never applied. An unsupported matchingMethod would fail validation, not simply result in ungrouped incidents.

  • ✗

    The rule is not enabled properly.

    Why it's wrong here

    The rule is actually healthy: enabled is true and incidentCreation is true, so the rule is actively running and producing incidents. If it weren't enabled properly, you would see no alerts or incidents at all rather than one incident per alert. The observed behavior is fully consistent with a correctly enabled rule whose groupingConfiguration is turned off.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.