SC-200 Practice Question 3737
Exam: SC-200
Domain: Manage a security operations environment
Difficulty: easy
What feature in Microsoft Sentinel automatically links related alerts generated within a time window into a single compound incident to prevent alert fatigue?
Answer Options
A
Alert grouping rules based on matching entities and time windows
B
Deleting non-critical alerts from the database
C
Assigning all alerts to a single junior analyst
D
Turning off email notifications
Correct Answer
A: Alert grouping rules based on matching entities and time windows
Explanation
Incident grouping (Alert grouping) in Microsoft Sentinel analytics rules groups alerts matching specific entities (like account or IP) into a single incident.