Subdomain 1.1: Configure automation for Microsoft Defender XDR and Microsoft Sentinel
1.Two incidents in the Defender portal involve the same compromised device and overlapping timestamps, and Defender's correlation engine determines they should be merged. However, one incident is assigned to Analyst A and the other is assigned to Analyst B. What happens?
- A.The incidents remain separate until the assignment conflict is resolved, after which they can be merged manually
- B.Defender automatically reassigns both incidents to Analyst A before merging them
- C.The incidents merge automatically, and the assignment field is left blank on the resulting incident
- D.The lower-severity incident is automatically closed without any of its alerts being transferred
Show answer & explanation
Correct answer: A — The incidents remain separate until the assignment conflict is resolved, after which they can be merged manually
- A. Incidents assigned to two different people are excluded from automatic merging; once the conflicting assignment is removed, an analyst can merge the incidents manually.
- B. Defender does not reassign incidents on its own to force a merge; the differing assignment is one of the conditions that blocks the automatic merge from happening at all.
- C. No automatic merge occurs while the assignments differ, so there is no resulting merged incident with a blank assignment field.
- D. Closing an incident is not how differing assignments are handled, and a real merge always migrates alerts into the target incident rather than discarding them.