SC-200 Practice Question 3737

Exam: SC-200
Domain: Manage a security operations environment
Difficulty: easy
What feature in Microsoft Sentinel automatically links related alerts generated within a time window into a single compound incident to prevent alert fatigue?

Answer Options

A
Alert grouping rules based on matching entities and time windows
B
Deleting non-critical alerts from the database
C
Assigning all alerts to a single junior analyst
D
Turning off email notifications

Correct Answer

A: Alert grouping rules based on matching entities and time windows

Explanation

Incident grouping (Alert grouping) in Microsoft Sentinel analytics rules groups alerts matching specific entities (like account or IP) into a single incident.