SC-200 Manage a security operations environment Practice Question
You are the security operations lead for a multinational company that uses Microsoft Sentinel in a single workspace. You have recently onboarded 10 new business units, each with their own analytics rules and automation. The security team is overwhelmed by the number of low-fidelity incidents generated. You need to reduce noise without disabling critical detections. You must ensure that each business unit retains ownership of their incidents and can customize their own suppression rules. You also need centralized reporting on incident trends across all business units. You have identified that many low-fidelity alerts come from a common set of data sources. What should you do?
⚠ Common exam trap
Test-takers frequently confuse reducing noise with simply hiding or closing incidents after they are generated, rather than preventing the noise at the analytics rule level through alert suppression, which is the only option that reduces incident volume while preserving data fidelity and per-unit customization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a separate analytics rule for low-fidelity alerts that uses alert suppression to group similar alerts.
Creating a separate analytics rule for low-fidelity alerts with alert suppression enabled allows you to group similar alerts into a single incident, reducing noise without disabling the underlying data connectors or critical detections. This approach preserves each business unit's ownership of their incidents and enables them to customize suppression rules via automation rules or analytics rule settings, while centralized reporting on incident trends remains intact because the workspace still ingests all alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the data connectors that produce the most noise.
Why it's wrong here
Disabling data connectors removes all alerts from those sources, eliminating detection coverage for potentially critical events. Even noisy connectors may contain high-severity signals that other analytics rules depend on. Noise should be reduced by tuning rule thresholds or using suppression, not by cutting off the data pipeline entirely.
- ✗
Create an automation rule that automatically closes low-severity incidents.
Why it's wrong here
Creating an automation rule to close low-severity incidents does not prevent the incidents from being created, so alert-to-incident processing and storage costs remain. These incidents still consume analyst attention and automation runbook cycles before being closed. Additionally, automatic closure can mask early indicators of a larger attack, especially if low-severity events later correlate with other activity. It treats the symptom without addressing the root cause of alert noise.
- ✓
Create a separate analytics rule for low-fidelity alerts that uses alert suppression to group similar alerts.
Why this is correct
Alert suppression in a dedicated analytics rule groups similar low-fidelity alerts into a single incident, reducing the incident queue while retaining signal awareness. Because it is a separate rule, its suppression settings can be tuned independently without impacting high-fidelity detection rules. This balances detection capability with operational efficiency, making it the only option that actually lowers incident volume without losing data.
- ✗
Create a workbook that filters out low-severity incidents from the dashboard.
Why it's wrong here
A workbook that filters low-severity incidents from the dashboard only alters the displayed view; every incident is still generated, stored, and processed by backend systems. It does not affect alert rules, incident creation, or resource consumption, so SOC analysts still have to triage and manage those items. The underlying alert fatigue and cost remain unchanged, making this a cosmetic fix rather than a functional reduction.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.