Courseiva

SC-200 Respond to security incidents Practice Question

Your company uses Microsoft Sentinel. A security analyst receives an incident that includes a large number of alerts from a single data source. The analyst needs to identify which alerts are duplicates or related so they can focus on unique threats. Which feature should the analyst use?

⚠ Common exam trap

SC-200 often tests the confusion between alert grouping (deduplication/correlation at incident creation) and entity mapping (field mapping for correlation), causing candidates to pick entity mapping when the question asks about reducing duplicate alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Alert grouping

Alert grouping in Microsoft Sentinel automatically combines related alerts into a single incident, reducing noise so analysts can focus on unique threats. It uses machine learning to correlate alerts that share entities, timing, or patterns, directly addressing the need to identify duplicates or related alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Alert grouping

    Why this is correct

    Alert grouping is a built-in setting in Sentinel analytics rules that determines when a new incident should be created versus when an alert should be added to an existing incident. You can group by entity, by alert attributes, or within a specified time window, and you can also set the incident title. This directly reduces alert fatigue by consolidating related alerts, making it the correct answer.

  • ✗

    Investigation graph

    Why it's wrong here

    The investigation graph is an interactive visualizer that shows connections between entities involved in an alert or incident. It lets you pivot across related users, hosts, IP addresses, and other data to uncover the blast radius. It does not consolidate multiple alerts into a single incident, so it is not the mechanism used to reduce alert noise by grouping.

  • ✗

    Entity mapping

    Why it's wrong here

    Entity mapping is a rule configuration that extracts fields from log data and identifies them as entities such as accounts, hosts, or IP addresses. This enriches each alert with structured context that can be used for correlation and investigation, but it has no role in merging or grouping alerts together. It is a separate capability from incident creation settings.

  • ✗

    Automation rules

    Why it's wrong here

    Automation rules automate incident management actions such as tagging, assigning, or running playbooks in response to incident triggers. They operate after an incident has already been created and can react to its properties, but they cannot control whether multiple alerts are collapsed into one incident. That grouping logic is defined directly in the analytics rule's incident creation configuration.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.