Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO actions should you take when configuring Microsoft Sentinel to minimize false positives from an analytics rule?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Map entities correctly

Option B (Map entities correctly) is correct because accurate entity mapping (for example, mapping Account, Host, or IP custom entities in the rule's entity mapping section) lets Sentinel correlate and enrich alerts with the right context, so benign activity isn't misattributed and duplicate or unrelated alerts aren't generated. Option D (Adjust the rule's query threshold) is correct because tuning the rule's KQL query — for example, raising the count or time-window threshold, filtering known-good accounts, or adding exclusions — directly reduces the volume of low-fidelity matches that become false-positive incidents. Option A is not a false-positive reduction measure; a playbook that auto-closes low-severity alerts only handles alerts after they are created and does not stop them from firing. Option C (Enable incident creation automatically) actually increases noise by turning every matching alert into an incident rather than suppressing false positives. Option E (Configure alert grouping) consolidates related alerts into fewer incidents but does not reduce the underlying false-positive detections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a playbook to automatically close low-severity alerts

    Why it's wrong here

    A playbook that closes low-severity alerts acts after incidents are generated, so it suppresses noise downstream rather than reducing false-positive detections. Playbooks suit automated response and enrichment; tuning the rule's query, thresholds or entity mappings is what prevents spurious alerts being raised.

  • ✓

    Map entities correctly

    Why this is correct

    Mapping entities correctly ties alerts to the right accounts, hosts and IP addresses, so Microsoft Sentinel correlates activity accurately and stops unrelated events triggering the rule. This directly reduces false positives by ensuring entity-based logic matches genuine incidents.

  • ✗

    Enable incident creation automatically

    Why it's wrong here

    Automatic incident creation governs whether generated alerts become incidents; it does not affect whether those alerts are false positives. Enabling it is appropriate when you want every alert triaged as an incident, but it cannot reduce spurious detections from the rule's logic.

  • ✓

    Adjust the rule's query threshold

    Why this is correct

    Raising the query threshold means the rule only fires when the specified number of results is exceeded, filtering out low-volume benign activity. This cuts false positives while the rule remains enabled and continues detecting genuine threats above that threshold.

  • ✗

    Configure alert grouping

    Why it's wrong here

    Alert grouping merges related alerts into a single incident, reducing incident volume but not the number of false-positive alerts the rule generates. It is valuable for managing noisy multi-entity detections, yet the question asks how to minimise false positives at the analytics rule itself.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.