MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a Microsoft 365 administrator for Tailspin Toys. The security team wants to reduce the number of alerts generated by Microsoft Defender for Endpoint on Windows 10 devices that run a custom line-of-business application. The application performs many legitimate network connections that trigger the 'Suspicious network connection' alert. You need to suppress these alerts while still investigating all other alerts. What should you create in the Microsoft 365 Defender portal?
⚠ Common exam trap
Candidates often confuse an allow indicator of compromise with alert suppression, when an allow IoC changes blocking behavior but does not stop behavioral alerts from being generated.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An alert suppression rule for the 'Suspicious network connection' alert scoped to the affected devices or application.
Alert suppression rules in Microsoft Defender for Endpoint are designed to reduce alert noise by suppressing specific alerts within a defined scope, such as a device group, file hash, IP address, or URL. Scoping the rule to the line-of-business application and its devices silences the known false positive while preserving visibility into all other alerts. Indicators of compromise change block or allow behavior, and AIR or custom detections act after or alongside alerts rather than suppressing them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An automated investigation and response (AIR) playbook that closes the alert automatically.
Why it's wrong here
AIR playbooks and automated investigation can remediate or close alerts, but they act after the alert is generated and may take remediation actions that are unnecessary for a false positive. They do not prevent the alert from appearing, so the security team would still see the noise. Suppression is the correct mechanism to stop the alert from being created.
- ✓
An alert suppression rule for the 'Suspicious network connection' alert scoped to the affected devices or application.
Why this is correct
Alert suppression rules in Microsoft Defender for Endpoint let you suppress specific alerts for defined scopes, such as a device group, file hash, IP address, or URL. Scoping the rule to the custom application and the affected devices stops the noisy alert while leaving all other detections active, which matches the requirement to keep investigating other alerts.
- ✗
An indicator of compromise (IoC) for the application's executable hash with the action Allow.
Why it's wrong here
Indicators of compromise with the Allow action are used to permit files, IP addresses, URLs, or certificates that would otherwise be blocked. They do not suppress alerts generated by behavioral detections such as suspicious network connections. Creating an allow IoC here would change blocking behavior but would not stop the noisy alerts the team wants to reduce.
- ✗
A custom detection rule that queries DeviceNetworkEvents and marks the connections as benign.
Why it's wrong here
Custom detection rules create new alerts based on Advanced Hunting queries; they do not suppress existing built-in detections. Adding a rule to mark connections as benign has no effect on the 'Suspicious network connection' alert. The analyst would still receive the original alert, and the custom rule could add additional noise rather than reduce it.
Go deeper
Related to this question
Learn chapter
Exchange Mobile Device Policies (OWA)
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Device group
A device group is a logical collection of devices managed together for applying policies, configurations, and updates in an enterprise IT environment.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.