mediumMultiple Choice
SC-200 Practice Question: A Defender for Cloud alert repeatedly fires for a…
A Defender for Cloud alert repeatedly fires for a known test VM used by the security team. The alert type is valid, but it should not create noise for that VM. What should the analyst configure?
⚠ Common exam trap
A common mix-up: candidates confuse alert suppression (which dismisses alerts without affecting detection) with disabling a security plan or modifying secure score, leading them to choose overly broad or irrelevant actions like disabling Defender for Servers or deleting recommendations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an alert suppression rule scoped to the test VM and alert type.
An alert suppression rule in Microsoft Defender for Cloud allows you to define a scope (e.g., a specific VM) and a condition (e.g., a specific alert type) to automatically dismiss alerts that are valid but not actionable for that resource. This reduces noise without affecting detection coverage for other resources. The rule is configured at the subscription or resource group level and applies only to matching alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an alert suppression rule scoped to the test VM and alert type.
Why this is correct
Creating an alert suppression rule scoped to the test VM and the specific alert type is the correct noise-control method in Defender for Cloud. You define conditions such as the VM resource and alert name, so truly benign alerts from this known test asset are hidden or muted without disabling any threat detection. Other VMs remain fully monitored, and if the alert pattern changes, you can edit or disable the rule.
- ✗
Disable Defender for Servers for the entire subscription.
Why it's wrong here
Disabling Defender for Servers at the subscription level is overbroad and dangerous because it turns off threat detection for every VM in the subscription, including production workloads. A single noisy test VM does not justify removing protection from unrelated resources. This blunt action would leave all covered machines blind to malicious activity and would also lower your Secure Score, whereas a scoped suppression rule only hides the specific benign alert.
- ✗
Change the VM name.
Why it's wrong here
Changing the VM name will not stop the alert because Defender for Cloud generates alerts from event and activity signals such as anomalous behaviors or suspicious processes, not from the machine name. The same benign activity will still trigger the detection under the new hostname, and you might also break automation, runbooks, or monitoring that reference the original name. The correct fix is to suppress the alert itself, not rename the asset.
- ✗
Delete the recommendation from secure score.
Why it's wrong here
Secure Score recommendations are not a noise-control surface: they are immutable assessments generated by Defender for Cloud policies, and you cannot simply delete a recommendation from the portal or API. Attempting to remove it would not prevent alerts from firing, and it would distort your security posture by hiding a real gap. You can use exemptions or make a business justification, but that doesn't suppress alert generation—only alert suppression rules do.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.