Courseiva

SC-200 Respond to security incidents Practice Question

Your Microsoft Sentinel workspace is receiving a high volume of false positive alerts from a specific analytics rule. You need to suppress these alerts without disabling the rule. Which feature should you use?

⚠ Common exam trap

SC-200 often tests the distinction between suppressing alerts at the rule level versus closing incidents after the fact with automation rules — candidates pick automation because it sounds like 'handling' the noise, but it does not prevent incident creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure alert suppression in the analytics rule

Alert suppression in a Microsoft Sentinel analytics rule lets you define conditions (such as matching entity, IP address, or account) under which subsequent matching alerts are suppressed for a configurable time window. This stops the false-positive noise without turning off the rule, so genuine detections from other entities or conditions still fire. It is configured directly on the analytics rule's 'Incident settings' / suppression section, making it the precise tool for this requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an automation rule to close incidents

    Why it's wrong here

    Automation rules are triggered after an incident or alert is created, not before, so they cannot stop the analytic rule from generating alerts. Even if an automation rule immediately closes an incident, the underlying alert remains in the workspace, still counts toward alert volume, and a new incident can be created next time the condition recurs. Closing incidents addresses the symptom of high incident count, not the cause of high alert traffic.

  • ✗

    Adjust the alert threshold in the analytics rule

    Why it's wrong here

    The threshold in a scheduled analytics rule (e.g., 'Query results > 5') controls how many matches are required before an alert is created, so raising it makes the rule less sensitive. However, threshold adjustment applies globally to the rule's detection logic and does not suppress a specific noisy condition; if a high-volume event still produces enough results to exceed the new threshold, an alert is still created each time. It also risks increasing false negatives by lowering detection coverage.

  • ✓

    Configure alert suppression in the analytics rule

    Why this is correct

    The correct approach is to enable Alert suppression in the analytics rule's 'Set rule logic' settings. When the rule fires, you can configure it to stop running the query for a specified duration (e.g., 1, 6, or 12 hours), so the same matching condition does not immediately generate multiple duplicate alerts. This suppresses additional alerts from that rule during the suppression window while preserving the rule for future detections.

  • ✗

    Disable incident creation for the rule

    Why it's wrong here

    Disabling 'Create an incident from alerts triggered by this rule' stops Sentinel from converting the rule's alerts into incidents, but the analytic rule still runs and still generates alerts. Those alerts remain visible in the Alerts queue, consume storage and ingestion capacity, and can still trigger downstream integrations. This only lowers the number of incidents, not the overall alert volume, so it does not solve the underlying noise problem.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.