Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium

A security operations center (SOC) manager is reviewing Microsoft Sentinel incidents and notices that many low-priority alerts from a specific application are generating separate incidents, leading to alert fatigue. The manager wants to group these related alerts into a single incident to streamline investigations. Which incident setting should the manager adjust within the analytics rule that generates these alerts?

  1. AAlert enrichment
  2. BRule query schedule
  3. CSuppression
  4. DEvent grouping
Show answer & explanation

Correct answer: D. Event grouping

The 'Event grouping' setting within an analytics rule allows you to define how alerts generated by the rule are grouped into incidents. By configuring this, related alerts can be combined into a single incident, reducing alert fatigue and simplifying incident management.

Why the other options are wrong

  • A. Alert enrichment adds more context to alerts but does not control their grouping into incidents.
  • B. Rule query schedule defines how often the query runs, not how alerts are grouped into incidents.
  • C. Suppression prevents certain alerts from being generated, which is different from grouping existing alerts into incidents.

Microsoft Sentinel Incident Grouping

A feature in Microsoft Sentinel analytics rules that controls how multiple alerts generated by a rule are combined into a single incident.

  • Reduces alert fatigue and improves incident management efficiency.
  • Can group alerts based on entities, custom fields, or all alerts into one.
  • Configured within the 'Incident settings' section of an analytics rule.

Memory trick: Grouping is like putting all the related 'puzzle pieces' of an attack into one box.

More Mitigate threats using Microsoft Sentinel questions