SC-200 Manage a security operations environment Practice Question
Which TWO actions should you take when configuring Microsoft Sentinel to minimize false positives from an analytics rule?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Map entities correctly
Option B (Map entities correctly) is correct because accurate entity mapping (for example, mapping Account, Host, or IP custom entities in the rule's entity mapping section) lets Sentinel correlate and enrich alerts with the right context, so benign activity isn't misattributed and duplicate or unrelated alerts aren't generated. Option D (Adjust the rule's query threshold) is correct because tuning the rule's KQL query — for example, raising the count or time-window threshold, filtering known-good accounts, or adding exclusions — directly reduces the volume of low-fidelity matches that become false-positive incidents. Option A is not a false-positive reduction measure; a playbook that auto-closes low-severity alerts only handles alerts after they are created and does not stop them from firing. Option C (Enable incident creation automatically) actually increases noise by turning every matching alert into an incident rather than suppressing false positives. Option E (Configure alert grouping) consolidates related alerts into fewer incidents but does not reduce the underlying false-positive detections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a playbook to automatically close low-severity alerts
Why it's wrong here
A playbook that closes low-severity alerts acts after incidents are generated, so it suppresses noise downstream rather than reducing false-positive detections. Playbooks suit automated response and enrichment; tuning the rule's query, thresholds or entity mappings is what prevents spurious alerts being raised.
- ✓
Map entities correctly
Why this is correct
Mapping entities correctly ties alerts to the right accounts, hosts and IP addresses, so Microsoft Sentinel correlates activity accurately and stops unrelated events triggering the rule. This directly reduces false positives by ensuring entity-based logic matches genuine incidents.
- ✗
Enable incident creation automatically
Why it's wrong here
Automatic incident creation governs whether generated alerts become incidents; it does not affect whether those alerts are false positives. Enabling it is appropriate when you want every alert triaged as an incident, but it cannot reduce spurious detections from the rule's logic.
- ✓
Adjust the rule's query threshold
Why this is correct
Raising the query threshold means the rule only fires when the specified number of results is exceeded, filtering out low-volume benign activity. This cuts false positives while the rule remains enabled and continues detecting genuine threats above that threshold.
- ✗
Configure alert grouping
Why it's wrong here
Alert grouping merges related alerts into a single incident, reducing incident volume but not the number of false-positive alerts the rule generates. It is valuable for managing noisy multi-entity detections, yet the question asks how to minimise false positives at the analytics rule itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.