mediumMultiple Select
SC-200 Practice Question: A security analyst is triaging security alerts in…
A security analyst is triaging security alerts in Microsoft Defender for Cloud. Which of the following are valid ways to suppress a specific alert type to reduce noise? (Choose all that apply.)
⚠ Common exam trap
Candidates often confuse 'suppression' with 'automation' or 'severity modification', thinking that changing severity or adding a response action will reduce noise, when in fact only suppression rules (or automatic dismissal rules) actually remove alerts from the queue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an alert suppression rule based on alert entity
Microsoft Defender for Cloud allows you to create suppression rules that automatically dismiss alerts based on specific alert entities (such as alert ID, title, or severity) to reduce noise. These rules are configured in the security alerts settings and can be scoped to a subscription or management group, ensuring that alerts matching the defined criteria are silently dismissed without generating incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an alert suppression rule based on alert entity
Why this is correct
Alert suppression rules in Microsoft Defender XDR and Sentinel allow you to build conditions directly around entity attributes such as IP address, hostname, or user account. When an alert is generated that matches the specified entity, the rule automatically hides it from the queue, preventing it from consuming analyst time. This is a true suppression mechanism because it acts at the detection level, reducing alert volume before triage.
- ✗
Modify the alert's severity
Why it's wrong here
Modifying an alert's severity is a manual or automated adjustment to its impact classification, not a suppression action. Even if you lower the severity to Informational, the alert still exists in the alert queue and may still contribute to incident creation, just with a lower prioritization score. It changes how an analyst ranks the alert but does not hide, dismiss, or otherwise prevent it from being processed.
- ✗
Set an automatic response action
Why it's wrong here
An automatic response action—such as a playbook in Microsoft Sentinel or a response action in Defender XDR—runs after the alert has already been generated. These actions can contain threats, gather context, or trigger remediation, but they do not retroactively suppress the alert or remove it from the queue. The alert remains visible and must be separately handled or closed; therefore, this is not a suppression mechanism.
- ✓
Define a rule to automatically dismiss alerts that meet criteria
Why this is correct
You can configure a suppression rule that automatically dismisses newly created alerts when they meet specific criteria, such as alert name, severity, or tactical group. This rule acts as a filter that closes matching alerts immediately, effectively hiding them from the active queue while retaining them for audit. Unlike a purely entity-based rule, this approach is driven by broader alert characteristics, but it is a legitimate suppression strategy and is functionally correct here.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.