Courseiva

SC-200 Respond to security incidents Practice Question

An organization uses Microsoft Defender for Cloud Apps to detect anomalous behavior. An alert indicates that a user has signed in from an impossible travel scenario. The SOC analyst confirms the alert is a false positive due to a VPN. What should the analyst do to prevent future false positives for this user?

⚠ Common exam trap

SC-200 often tests the misconception that changing a user's location in Entra ID or disabling the detection rule is the right fix — the correct scoped remediation is adding the VPN IP range to trusted IP addresses in Defender for Cloud Apps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the VPN IP range to the trusted IP addresses in Defender for Cloud Apps.

The correct action is to add the VPN IP range to the trusted IP addresses in Defender for Cloud Apps (D). Trusted IP addresses are excluded from impossible travel and other anomalous location detections, so legitimate VPN egress IPs will not trigger false positives. This is a targeted, user-impacting fix that preserves detection for other scenarios. Changing Entra ID location or disabling the rule are not appropriate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the user's location in Microsoft Entra ID.

    Why it's wrong here

    Editing the user's location attribute in Microsoft Entra ID corrupts identity data used by conditional access and other sign-in risk evaluations, without suppressing the Defender for Cloud Apps alert. It is tempting because location feeds anomaly detection, but the correct approach is a scoped alert suppression or IP allowlist for the VPN.

  • ✗

    Ignore the alert and continue monitoring.

    Why it's wrong here

    Ignoring the alert leaves the detection rule unchanged, so the same false positive recurs on every future VPN sign-in and no suppression is recorded. Ignoring is tempting as a low-effort response to a confirmed benign alert, and would be correct for a genuine one-off event, but not for a recurring VPN pattern.

  • ✗

    Disable the impossible travel detection rule.

    Why it's wrong here

    Disabling the detection rule removes impossible travel coverage for every user in the tenant, not just this one, creating a broad blind spot. Disabling is tempting when a rule generates persistent noise, and would be correct if the detection were fundamentally unusable, but here the false positive stems from one user's VPN.

  • ✓

    Add the VPN IP range to the trusted IP addresses in Defender for Cloud Apps.

    Why this is correct

    Adding the VPN IP range to Defender for Cloud Apps trusted IP addresses suppresses impossible-travel detections originating from those addresses, since the engine treats trusted ranges as known-good locations. This directly addresses the confirmed false positive caused by VPN egress, preventing recurrence for this user without disabling the detection policy itself.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.