nerdexam
Microsoft

SC-200 · Question #36

You provision Azure Sentinel for a new Azure subscription. You are configuring the Security Events connector. While creating a new rule from a template in the connector, you decide to generate a new…

The correct answer is A. user D. computer. IP address data is removed from the query in the | summarize, and is not mapped to the IP We can see that the Account and Computer were mapped to entities and were returned in the 'summarize' section.

Submitted by lukas.cz· Apr 18, 2026Configure protections and detections

Question

You provision Azure Sentinel for a new Azure subscription. You are configuring the Security Events connector. While creating a new rule from a template in the connector, you decide to generate a new alert for every event. You create the following rule query. By which two components can you group alerts into incidents?Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Exhibit

SC-200 question #36 exhibit

Options

  • Auser
  • Bresource group
  • CIP address
  • Dcomputer

How the community answered

(52 responses)
  • A
    85% (44)
  • B
    10% (5)
  • C
    6% (3)

Explanation

IP address data is removed from the query in the | summarize, and is not mapped to the IP We can see that the Account and Computer were mapped to entities and were returned in the 'summarize' section.

Topics

#Azure Sentinel#Analytics Rules#Alert Grouping#Incident Creation

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice