SC-200 Respond to security incidents Practice Question
An organization uses Microsoft Defender for Cloud Apps to detect anomalous behavior. An alert indicates that a user has signed in from an impossible travel scenario. The SOC analyst confirms the alert is a false positive due to a VPN. What should the analyst do to prevent future false positives for this user?
⚠ Common exam trap
SC-200 often tests the misconception that changing a user's location in Entra ID or disabling the detection rule is the right fix — the correct scoped remediation is adding the VPN IP range to trusted IP addresses in Defender for Cloud Apps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the VPN IP range to the trusted IP addresses in Defender for Cloud Apps.
The correct action is to add the VPN IP range to the trusted IP addresses in Defender for Cloud Apps (D). Trusted IP addresses are excluded from impossible travel and other anomalous location detections, so legitimate VPN egress IPs will not trigger false positives. This is a targeted, user-impacting fix that preserves detection for other scenarios. Changing Entra ID location or disabling the rule are not appropriate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the user's location in Microsoft Entra ID.
Why it's wrong here
Editing the user's location attribute in Microsoft Entra ID corrupts identity data used by conditional access and other sign-in risk evaluations, without suppressing the Defender for Cloud Apps alert. It is tempting because location feeds anomaly detection, but the correct approach is a scoped alert suppression or IP allowlist for the VPN.
- ✗
Ignore the alert and continue monitoring.
Why it's wrong here
Ignoring the alert leaves the detection rule unchanged, so the same false positive recurs on every future VPN sign-in and no suppression is recorded. Ignoring is tempting as a low-effort response to a confirmed benign alert, and would be correct for a genuine one-off event, but not for a recurring VPN pattern.
- ✗
Disable the impossible travel detection rule.
Why it's wrong here
Disabling the detection rule removes impossible travel coverage for every user in the tenant, not just this one, creating a broad blind spot. Disabling is tempting when a rule generates persistent noise, and would be correct if the detection were fundamentally unusable, but here the false positive stems from one user's VPN.
- ✓
Add the VPN IP range to the trusted IP addresses in Defender for Cloud Apps.
Why this is correct
Adding the VPN IP range to Defender for Cloud Apps trusted IP addresses suppresses impossible-travel detections originating from those addresses, since the engine treats trusted ranges as known-good locations. This directly addresses the confirmed false positive caused by VPN egress, preventing recurrence for this user without disabling the detection policy itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.