SC-200 Manage a security operations environment Practice Question
Your Microsoft Defender XDR environment is experiencing high false positive rates for a specific type of alert. You need to reduce the noise without completely disabling the alert. What is the most effective method?
⚠ Common exam trap
Many exam-takers confuse suppression rules (which hide alerts) with tuning the detection logic itself, leading them to choose Option B because they think hiding the alert is equivalent to reducing noise, but it does not reduce the underlying detection rate or resource consumption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom detection rule to tune the detection logic.
Creating a custom detection rule allows you to refine the detection logic by adding specific conditions, such as excluding known benign processes or IP addresses, thereby reducing false positives while retaining the alert's core detection capability. This approach directly tunes the detection mechanism rather than masking or disabling it, aligning with the goal of reducing noise without completely disabling the alert.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a custom detection rule to tune the detection logic.
Why this is correct
Creating a custom detection rule in Microsoft 365 Defender lets you modify the underlying KQL query, schedule, and thresholds that govern when an alert triggers. This fine-grained approach directly addresses the detection logic responsible for false positives while preserving the rule’s intended coverage. Unlike suppression or automation, this reduces alert noise at the source, ensuring only relevant events generate incidents, and it keeps the original built-in rule available for baseline comparison.
- ✗
Create a suppression rule for the alert.
Why it's wrong here
A suppression rule in Microsoft 365 Defender only hides the alert from the queue and stops notifications; it does not change the detection logic that produced the false positive. The detection still fires and consumes system resources, and the suppressed alerts remain visible in advanced hunting, meaning the root cause remains unaddressed. This makes suppression a temporary, presentation-level fix that fails to prevent repeated false positives and offers no improvement to detection accuracy.
- ✗
Use an automation rule to automatically close the false positive incidents.
Why it's wrong here
Automation rules in Microsoft 365 Defender operate on incidents that have already been created, not on the underlying alert generation process. By automatically closing false-positive incidents, you’re only reacting to the symptom post-detection, leaving the alert pipeline active and generating noise that must still be processed by automation and logging. This approach increases operational overhead and can mask true positives if the closing criteria are overly broad, without ever tuning the detection query to reduce actual false positives.
- ✗
Disable the built-in detection rule.
Why it's wrong here
Disabling the built-in detection rule is a blanket measure that eliminates all alerts from that rule, including true positives, which can leave your environment blind to real threats. This removes the detection entirely rather than refining its logic, and it requires a global change that affects all tenants or workspaces without the ability to scope conditions. It is a last-resort action that sacrifices security coverage, whereas a custom detection rule allows you to adjust logic while keeping detection active.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.