Courseiva

SC-200 Manage a security operations environment Practice Question

You are the security operations lead for a multinational company using Microsoft Sentinel. You have deployed a custom analytics rule that uses a KQL query to detect anomalous outbound network traffic. The rule runs every hour and looks back 24 hours. Recently, the rule has been generating a high number of false positives. You need to tune the rule to reduce false positives without missing genuine threats. The rule currently triggers when the count of outbound connections to a single IP exceeds 100 in an hour. You analyze the data and find that legitimate cloud services often trigger the rule. What should you do?

⚠ Common exam trap

SC-200 often tests the difference between tuning (refining the query) and suppressing (hiding alerts) — candidates must recognize that suppression can create blind spots, while query refinement is the preferred method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the KQL query to exclude traffic to known benign IP ranges.

The most effective way to reduce false positives without missing genuine threats is to refine the KQL query to exclude traffic to known benign IP ranges, such as those belonging to legitimate cloud services. This preserves the detection logic for suspicious IPs while eliminating noise from trusted sources. It is a targeted tuning approach that maintains threat coverage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the rule and create a new one with a different query.

    Why it's wrong here

    Disabling the rule and rewriting the query discards tuned detection logic and creates a coverage gap while the replacement is validated, without addressing why legitimate cloud services match. Rebuilding suits fundamentally flawed logic, not a rule whose only defect is unexcluded known-good entities.

  • ✗

    Increase the threshold to 200 connections per hour.

    Why it's wrong here

    Raising the threshold to 200 leaves the query logic unchanged, so legitimate cloud services exceeding that count still trigger, while genuine low-volume exfiltration below 200 is missed. Threshold increases suit stable environments with predictable baselines, not dynamic cloud traffic requiring entity-based exclusion.

  • ✗

    Configure a suppression rule to automatically close incidents from those IPs.

    Why it's wrong here

    Suppression rules close matching incidents after they are created, so the underlying query still fires hourly and genuine threats sharing those IPs are silently hidden. Suppression suits known-benign recurring alerts where detection is acceptable, not tuning that must preserve visibility of real anomalies.

  • ✓

    Modify the KQL query to exclude traffic to known benign IP ranges.

    Why this is correct

    Excluding known benign IP ranges directly addresses the false positives caused by legitimate cloud services, since those destinations are the recurring trigger. Filtering them within the KQL query preserves detection of genuine anomalous outbound traffic to other IPs, satisfying the requirement to reduce noise without missing real threats.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.