SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender XDR and Microsoft Sentinel. The security operations center (SOC) team frequently receives false positive alerts for a specific user login pattern from a legacy application. You need to reduce alert fatigue without disabling the underlying detection rule. What should you configure?
⚠ Common exam trap
Watch out — candidates often confuse modifying the detection rule (options C or D) with configuring a separate suppression or response mechanism, failing to realize that automated investigation and remediation rules in Defender XDR can suppress alerts without altering the original detection logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an automated investigation and remediation rule in Microsoft Defender XDR to suppress alerts matching the legacy application pattern.
Configuring an automated investigation and remediation rule in Microsoft Defender XDR allows you to suppress alerts that match a specific pattern (e.g., legacy application login behavior) without disabling the underlying detection rule. This directly reduces alert fatigue by automatically closing or ignoring false positive alerts while keeping the rule active for genuine threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Sentinel bookmarks to mark the alerts as false positives.
Why it's wrong here
Microsoft Sentinel bookmarks are designed to capture, annotate, and preserve snapshots of query results for ongoing investigations; they act as markers for evidence you want to revisit later. Bookmarking a false-positive alert will not alter detection logic or prevent future alerts from being generated — it simply saves a static snapshot for manual review. Suppression requires an automated rule that operates on live alerts, not an investigative annotation tool.
- ✓
Configure an automated investigation and remediation rule in Microsoft Defender XDR to suppress alerts matching the legacy application pattern.
Why this is correct
An automated investigation and remediation rule in Microsoft Defender XDR can define precise conditions to match the legacy application's characteristic behavior, such as specific process names, users, or IP addresses, and then automatically take an action like closing or suppressing the alert. This works directly at the XDR layer, addressing the root cause of the false positive without modifying the underlying detection query or disabling broader threat visibility. It is the intended, scalable approach for recurring harmless patterns, requiring no manual intervention once configured.
- ✗
Create a watchlist in Microsoft Sentinel containing the legacy application's user accounts and use it in the rule.
Why it's wrong here
Microsoft Sentinel watchlists are essentially CSV-based reference lists used to enrich or correlate events in KQL queries — for example, mapping user account names to their expected roles or locations. They do not natively suppress alerts; to achieve suppression, you would have to modify each analytics rule's query logic to explicitly exclude list matches, adding complexity and maintenance burden. Furthermore, watchlists are a Sentinel feature and do not control alert generation in the Defender XDR pipeline where these alerts originate.
- ✗
Modify the analytics rule in Microsoft Sentinel to exclude the legacy application IP range.
Why it's wrong here
Editing the Sentinel analytics rule to exclude the legacy application's IP range would cause all detections involving that entire range to be ignored—not just the benign legacy application activity. IP ranges often contain a mix of legitimate and malicious traffic, so this broad exclusion could silently hide real attacks from that subnet. Additionally, the rule modification is static and needs constant updates as the application's IPs change, while the actual false-positive pattern remains unaddressed at the Defender XDR source.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.