Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel →mediumMultiple SelectObjective-mapped
Security Alerts Actions in Defender for Cloud — Suppression Rules and Playbooks
Which TWO actions can be performed using Microsoft Defender for Cloud's security alerts? (Choose two.)
Quick Answer
The answer is suppression rules and automated playbook triggers. These two actions are correct because Microsoft Defender for Cloud’s security alerts allow you to create suppression rules to automatically dismiss low-fidelity or known benign alerts, and you can configure a logic app playbook to run automatically when an alert is generated, enabling automated response workflows. On the AZ-500 exam, this concept tests your understanding of how to manage alert volume and orchestrate incident response without manual intervention—a common trap is assuming you can directly modify resources or set alert severity, but Defender for Cloud only triggers actions via playbooks and does not allow user-defined severity levels. Remember the memory tip: “Suppress the noise, automate the response”—if you can dismiss it or trigger a workflow, it’s a valid action; anything else is outside Defender for Cloud’s direct alert capabilities.
⚠ Common exam trap
It's easy for candidates to confuse the ability to modify alert severity (which is not supported) with the ability to create suppression rules or trigger automated responses, both of which are valid actions but require understanding of Defender for Cloud's specific capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create suppression rules to automatically dismiss alerts that meet specific criteria.
Microsoft Defender for Cloud allows you to create suppression rules that automatically dismiss alerts matching specific criteria, such as alert name, resource, or severity. This is useful for reducing noise from known benign activities without disabling the underlying security detection. Suppression rules are configured per alert type and can be set to expire after a defined period.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Directly modify the affected Azure resource's configuration from the alert.
Why it's wrong here
Alerts do not allow direct resource modification; they can trigger playbooks that modify resources.
- ✗
Export alerts to a third-party SIEM using continuous export.
Why it's wrong here
Alerts can be exported, but continuous export is for raw data, not alerts directly.
- ✗
Change the severity of an alert after it is generated.
Why it's wrong here
Alert severity is predefined by the detection logic and cannot be changed.
- ✓
Create suppression rules to automatically dismiss alerts that meet specific criteria.
Why this is correct
Suppression rules allow you to suppress alerts based on conditions.
- ✓
Trigger a logic app playbook automatically when an alert is generated.
Why this is correct
Playbooks can be triggered from alerts for automated response.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 194-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-500
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO actions can you perform using Microsoft Defender for Cloud's 'Security Alerts' page?
medium- ✓ A.View the kill chain of an alert.
- ✓ B.Suppress a specific alert for a defined time period.
- C.Run a remediation script against the affected resource.
- D.Create an automation rule to trigger a playbook.
- E.Modify the security policy of the subscription.
Why A: You can view the kill chain of an alert from the Security Alerts page. Option B is correct because you can suppress an alert (create suppression rules) from the Security Alerts page. Option C is incorrect because running a remediation script is not a built-in action on the Security Alerts page. Option D is incorrect because creating automation rules is done in Microsoft Sentinel, not directly on the Security Alerts page. Option E is incorrect because modifying the security policy is done via Azure Policy, not from Security Alerts.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.