Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel. A security analyst reports that an incident was automatically created for a sign-in from an unfamiliar location, but after investigation, it was determined to be a false positive. You need to reduce similar false positives in the future without affecting legitimate detections. What should you do?

⚠ Common exam trap

Candidates often confuse automation rules (which handle post-detection actions) with analytics rule modifications (which prevent detection at the source), leading them to choose option C instead of D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the analytics rule query to exclude sign-ins from the specific location.

Modifying the analytics rule query to exclude sign-ins from the specific location directly addresses the false positive at the detection logic level. This ensures that only sign-ins from that location are ignored, while all other unfamiliar location detections remain active, preserving legitimate detections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the analytics rule that created the incident.

    Why it's wrong here

    Disabling the analytics rule halts all incident creation from that rule, not just the false positives from that specific location. This removes visibility into genuinely malicious sign-ins from other locations and requires operational overhead to remember to re-enable the rule. A more surgical approach is to refine the rule's query logic to ignore only the offending location while retaining detection coverage elsewhere.

  • ✗

    Add the location to a watchlist and reference it in the analytics rule.

    Why it's wrong here

    Watchlists are designed for enrichment, correlation, and matching against data, not as a direct exclusion mechanism in an analytics rule. Even if you reference a watchlist in the KQL query, you must rewrite the query to filter out entries from that watchlist, which is effectively the same as adding an inline filter but with extra complexity and potential for list management errors. The correct approach is to target the false positive source directly in the rule's query with a simple 'where' clause.

  • ✗

    Create an automation rule to close similar incidents automatically.

    Why it's wrong here

    Automation rules execute after an incident is created, so they cannot prevent the initial alert from triggering. Auto-closing incidents based on similarity may hide true positives, degrade detections, and still consume resources for every generated alert. This does not address the root cause; instead, it treats the symptom and risks masking actual threats that share similar attributes with the false positives.

  • ✓

    Modify the analytics rule query to exclude sign-ins from the specific location.

    Why this is correct

    Modifying the analytics rule query to exclude sign-ins from the specific location is the precise fix because it filters out false positives at the source while preserving detection for all other events. In KQL, you would add a clause such as `| where Location != 'Country'` or filter by IP address, ensuring the rule's logic specifically ignores the unwanted sign-in origin. This keeps the rule active and focused on real anomalies, reducing alert noise without losing coverage for other suspicious activities.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.