Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO actions are valid ways to reduce the number of false positive incidents in Microsoft Sentinel without disabling analytics rules?

⚠ Common exam trap

Many exam-takers confuse reducing incident volume (via grouping or severity changes) with reducing false positives, but only query modifications or automation rules that close specific false incidents actually address the root cause of inaccurate detections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the rule's query to include additional filters.

Modifying the rule's query to include additional filters directly reduces false positives by narrowing the conditions that trigger an alert. This approach refines the detection logic without disabling the rule, ensuring only events that more precisely match the intended threat pattern generate incidents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the rule to group all alerts into a single incident per entity.

    Why it's wrong here

    Configuring alert grouping to create a single incident per entity consolidates multiple alerts into one incident, but it does not suppress the underlying false-positive detections. The analytics rule still fires for benign activity, and the resulting consolidated incident is simply a larger, merged false positive. This only reduces incident count through bucketing, not by improving detection precision.

  • ✗

    Increase the rule run frequency.

    Why it's wrong here

    Increasing the rule run frequency makes the KQL query execute more often, which proportionally raises the number of alert and incident creations rather than filtering out noise. A false-positive pattern will simply be surfaced more frequently, amplifying alert fatigue. Frequency adjustments affect scheduling, not the precision of the detection logic.

  • ✗

    Change the incident severity to Informational.

    Why it's wrong here

    Changing the incident severity to Informational only reclassifies the criticality of generated incidents; it does not prevent the analytics rule from creating them. False positives will still appear in the queue and consume investigation time, just with a lower severity label. Severity changes mask issues rather than eliminating the underlying false-positive generation.

  • ✓

    Modify the rule's query to include additional filters.

    Why this is correct

    Modifying the rule's query to include additional filters, such as excluding known-safe IP addresses or requiring specific event attributes, directly increases precision by removing benign activity from the detection logic. This addresses the root cause of false positives because the KQL query is the decision engine that determines which raw events become alerts. Properly scoped filters reduce incident volume while preserving genuine threat detection.

  • ✓

    Create an automation rule to close incidents that match certain criteria.

    Why this is correct

    Creating an automation rule that triggers on incident creation and automatically closes incidents matching certain criteria—like known-malicious-but-inert entities or false-positive titles—provides a post-detection remediation layer. This offloads the triage step by closing irrelevant incidents immediately, reducing analyst workload even though the underlying alerts still get generated. It complements query tuning by handling recurring false positives that cannot be fully filtered at query time.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.