SC-200 Manage a security operations environment Practice Question
You are a security operations analyst at a company that uses Microsoft Sentinel. You have enabled User and Entity Behavior Analytics (UEBA) to detect anomalies. A new alert fires indicating a user is logging in from an unusual location. However, the user is a known traveler. How can you reduce false positives without disabling the UEBA rule?
⚠ Common exam trap
It's easy for candidates to think disabling the rule or changing severity is the correct approach, but Microsoft specifically tests the ability to use entity-level exclusions to handle known exceptions without compromising overall detection coverage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the user to the entity behavior analytics exclusion list.
Microsoft Sentinel's UEBA allows you to add specific users to an entity behavior analytics exclusion list. This prevents the UEBA engine from generating alerts for that user's anomalous activities, such as logins from unusual locations, without disabling the underlying detection rule. This approach maintains detection coverage for other users while suppressing false positives for known travelers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add the user to the entity behavior analytics exclusion list.
Why this is correct
Adding the user to the entity behavior analytics exclusion list in Microsoft 365 Defender suppresses UEBA anomaly alerts for that specific entity only, leaving the 'unusual location' detection rule active for all other users. This is the targeted, least-privilege response for a legitimate traveler because it preserves the rule's ability to catch genuine account-compromise anomalies while preventing false positives tied to the known user's expected foreign sign-ins.
- ✗
Disable the UEBA anomaly rule for unusual locations.
Why it's wrong here
Disabling the UEBA anomaly rule for unusual locations is a global, rule-level change that stops alert generation for every user in the environment, not just the traveler. Unlike adding the user to an exclusion list, this removes all anomaly detection coverage for unusual geographies, which could allow a real impossible-travel or credential-theft incident elsewhere to go unnoticed. It is overly broad and degrades the overall security monitoring posture.
- ✗
Change the alert severity to Informational.
Why it's wrong here
Changing the alert severity to Informational only modifies the classification label attached to the alert; it does not suppress alert generation or prevent the incident from being created. The SOC will still have to triage the same unusual-location alert for the traveler, so the false-positive noise remains, and the severity change applies rule-wide, meaning a future high-confidence anomaly would also be downgraded and receive less attention than warranted.
- ✗
Increase the lookback period for the anomaly detection.
Why it's wrong here
Increasing the lookback period for anomaly detection expands the historical time window that UEBA uses to model the user's normal behavior, but it does not teach the model that a new foreign location is already authorized or expected. The traveler's sign-in from a new country will still be scored as anomalous relative to the existing baseline, and a longer lookback can introduce stale patterns that make the baseline less accurate rather than eliminating the alert. This also changes detection behavior globally for all entities, unlike a per-user exclusion.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.