User1 という名前のユーザーと WS1 という名前の Microsoft Sentinel ワークスペースを含む Azure サブスクリプションがあります。WS1 は Microsoft Defender for Cloud を使用します。
次の表に示す Microsoft セキュリティ分析ルールがあります。

ユーザー 1 が、ルール 1、ルール 2、ルール 3、およびルール 4 に一致するアクションを実行します。WS1 に作成されるインシデントの数はいくつですか。
正解:A
Microsoft Sentinel "Microsoft security" analytics rules (for products like Defender for Cloud) create incidents from alerts generated by that product. Even if multiple identical Microsoft security rules exist for the same product, a single incoming alert will result in one incident in the workspace, not one per rule.