Counting incidents created when four independent Sentinel analytics rules all fire for one action
You have an Azure subscription that contains a user named User1 and a Microsoft Sentinel workspace named WS1. WS1 uses Microsoft Defender for Cloud. You have the Microsoft security analytics rules shown in the following table. User1 performs an action that matches Rule1, Rule2, Rule3, and Rule4. How many incidents will be created in WS1? - 
Community Votes
71% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Each analytics rule independently creates alerts, and by default each alert becomes a separate incident unless alert grouping is explicitly configured; four distinct rules firing therefore yield four incidents.
A Sentinel workspace with four separate Microsoft security analytics rules; when User1's action matches all four, each rule generates its own alert and, with default per-rule settings, its own incident, so four incidents are created.
Assuming incident correlation merges them into one — Sentinel groups alerts into a single incident only when a rule's alert grouping is enabled, which is not the default and is not indicated by the scenario.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Sentinel analytics rules each generate alerts when their query matches, and each alert is created as its own incident unless that specific rule's alert grouping settings are configured to combine alerts. With four independent rules and no grouping indicated, Rule1 through Rule4 each produce one incident, for a total of four.Why the Other Options Are Wrong
Choosing 1 (A) assumes automatic cross-rule merging, which is not how analytics rules work by default; incident correlation in Defender XDR is separate from Sentinel analytics-rule incident creation. Options 2 (B) and 3 (C) would only apply if specific grouping were configured, which the scenario does not state.Community Comment Notes
The community favors D (71 votes). Tuitor01 and rkrau explain that each analytics rule generates its own incident unless grouping is enabled. A minority (Franc_Coetzee, HAjouz, sapphire) argues for A based on Defender XDR incident correlation, but that correlation is a different mechanism from Sentinel analytics-rule incident creation.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →