Microsoft SC-200 Question Answer
You provision Azure Sentinel for a new Azure subscription. You are configuring the Security Events connector.
While creating a new rule from a template in the connector, you decide to generate a new alert for every event. You create the following rule query.

By which two components can you group alerts into incidents? Each correct answer presents a complete
solution.
NOTE: Each correct selection is worth one point.
Microsoft SC-200 Summary
- Vendor: Microsoft
- Product: SC-200
- Update on: Dec 18, 2025
- Questions: 366

