Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

You are responsible for securing an Azure environment using Microsoft Defender for Cloud. You need to reduce the number of false positive security alerts for a specific Azure SQL Database. The database is regularly scanned by a legitimate security tool that generates alerts. What should you do?

⚠ Common exam trap

Watch out — candidates often confuse suppression rules (which filter alerts) with disabling detection rules or modifying firewall settings, thinking that blocking the source IP or disabling the rule entirely is the correct way to handle false positives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a suppression rule for the specific alert type and source IP address.

Microsoft Defender for Cloud allows you to create suppression rules to automatically filter out specific security alerts that are known to be benign. By configuring a suppression rule for the specific alert type and the source IP address of the legitimate security scanning tool, you can prevent those alerts from appearing in the security alerts queue without disabling broader detection for SQL databases. This approach reduces false positives while maintaining visibility into other potential threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the security alert rule for SQL databases in Defender for Cloud.

    Why it's wrong here

    Disabling the security alert rule for SQL databases in Defender for Cloud is an overly broad action: it turns off all SQL-related threat detections, including SQL injection, brute force, and anomalous access alerts, not just the noisy false positive. You would lose visibility into real attacks for the entire database service. The correct approach is to suppress only the specific alert type and source IP while leaving the rule and all other detection logic active.

  • ✗

    Exclude the database from the vulnerability assessment solution.

    Why it's wrong here

    Excluding the database from the vulnerability assessment (VA) solution stops the scanner from running on that resource, which eliminates periodic checks for misconfigurations, missing patches, and weak security settings. However, this does not affect the security alerts generated by Defender for Cloud's threat detection engine—the false positive you are seeing comes from the alert pipeline, not from the VA scan results. You would sacrifice compliance and security posture without solving the actual alert problem.

  • ✓

    Create a suppression rule for the specific alert type and source IP address.

    Why this is correct

    Creating a suppression rule for the specific alert type and source IP address is the targeted, recommended solution. Defender for Cloud lets you define a rule on an alert that automatically dismisses future matches based on properties like entity, IP address, or attack evidence, so benign scanning activity from that IP is ignored while all other alerts continue to fire. This reduces alert fatigue without disabling any detection capability.

  • ✗

    Modify the Azure SQL Database firewall rules to allow the scanning tool's IP.

    Why it's wrong here

    Modifying Azure SQL Database firewall rules to allow the scanning tool's IP does not influence Defender for Cloud's alert generation—firewall rules only control network connectivity, not the security analytics that detect suspicious activity. Even if the tool's traffic reaches the database, the detection logic still evaluates it against threat signatures and may issue the same alert. Moreover, opening a new IP on the firewall could increase the attack surface, making this both ineffective and a security risk.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.