Courseiva

How to Suppress False Positive Alerts in Microsoft Sentinel

Exhibit

Refer to the exhibit.
```
{
  "displayName": "Malicious URL detect",
  "description": "Detects access to known malicious URLs.",
  "tactics": ["InitialAccess"],
  "query": "UrlClickEvents | where ActionType == 'ClickAllowed' | where ThreatTypes contains 'Malicious' | project Timestamp, AccountUpn, Url",
  "queryFrequency": "PT1H",
  "queryPeriod": "PT1H",
  "triggerOperator": "GreaterThan",
  "triggerThreshold": 0,
  "suppressionDuration": "PT1H",
  "suppressionEnabled": false,
  "incidentConfiguration": {
    "createIncident": true,
    "groupingConfiguration": null
  }
}
```

You are reviewing a scheduled analytics rule in Microsoft Sentinel. What does the suppressionDuration setting affect?

⚠ Common exam trap

Test-takers frequently confuse suppressionDuration with incident grouping or query frequency settings, as candidates often think it controls how alerts are merged or how often the rule runs, rather than its actual purpose of temporarily halting alert creation after an alert fires.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It stops the rule from creating new alerts for that duration after an alert is generated.

The suppressionDuration setting in a Microsoft Sentinel scheduled analytics rule stops the rule from creating new alerts for a specified period after an alert is generated. This prevents alert fatigue by suppressing duplicate alerts from the same rule when the same conditions persist, allowing analysts to focus on unique incidents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It groups alerts into a single incident within that time window.

    Why it's wrong here

    Suppression duration in a Microsoft Sentinel scheduled analytics rule is not related to incident creation. Incident grouping is a separate configuration within the 'Incident settings' tab, where you choose to group all alerts triggered by the rule into a single incident or each alert into its own incident. Suppression only affects new alert generation after an alert already exists, not how incidents are formed from those alerts.

  • ✗

    It delays the execution of the query by that amount of time.

    Why it's wrong here

    Suppression duration does not introduce any delay in the execution of the rule's query. Query execution timing is governed by the query frequency (how often the rule runs) and the query period (how far back the query looks), both defined in the rule's scheduling settings. Suppression instead takes effect post-detection, meaning after an alert is created, it prevents further alert creation for the specified time without altering when or how the query executes.

  • ✗

    It determines how often the query runs.

    Why it's wrong here

    The frequency with which a scheduled analytics rule runs is controlled by the 'Run query every' setting, not by suppression duration. That frequency determines the cadence at which the rule's KQL query is executed against the workspace, while suppression duration only applies after the first alert is generated. Even if the query runs, suppression can still prevent it from generating a new alert during the quiet period.

  • ✓

    It stops the rule from creating new alerts for that duration after an alert is generated.

    Why this is correct

    When suppression is enabled, after the rule successfully generates an alert, Sentinel will not create any new alerts for the configured duration, even if subsequent query executions return matching results. This is a post-detection quiet period designed to avoid alert fatigue from repeated identical findings. The suppression timer resets only when a new alert is actually created, and the rule continues to run queries but suppresses their alerts until the duration lapses.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.