SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel. An incident has been identified as a false positive. What is the recommended action to prevent similar false positives in the future?
⚠ Common exam trap
Test-takers frequently confuse incident management actions (closing/classifying) with rule optimization, assuming that marking an incident as false positive automatically suppresses future similar alerts, when in fact it only affects the current incident's audit trail.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the analytics rule to reduce false positives
Modifying the analytics rule addresses the root cause of the false positive by adjusting the rule's query logic, thresholds, or entity mappings to reduce noise. In Microsoft Sentinel, analytics rules define the conditions that generate incidents; tuning these rules (e.g., changing frequency, lookback period, or adding exclusion filters) directly prevents similar false positives from recurring. Simply closing or classifying incidents does not prevent future occurrences, and deleting the rule would remove all detection capability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the analytics rule
Why it's wrong here
Deleting the analytics rule removes the detection logic entirely, which suppresses all future alerts generated by that rule and significantly broadens the security coverage gap. While it eliminates the noise, it also risks missing genuine malicious activity that shares similar patterns with the false positives. The better approach is to preserve the rule and tune its query, thresholds, or filters to balance detection fidelity with alert fatigue.
- ✗
Close the incident and set the classification to 'False positive'
Why it's wrong here
Closing the incident and setting the classification to 'False positive' only updates the incident's metadata in Microsoft Sentinel; it has no direct effect on the analytics rule that generated it. The classification is stored for audit and reporting purposes but does not automatically feed back into rule tuning or suppression logic. Future occurrences will still trigger the same alert, so this action is purely reactive and does not address the underlying detection configuration.
- ✓
Modify the analytics rule to reduce false positives
Why this is correct
Modifying the analytics rule is the correct action because it directly addresses the root cause of the false positives by adjusting the rule's query logic, threshold, or entity-specific filters. For example, you can add exclusions for known benign IP addresses, increase the aggregation window count, or refine the KQL query to be more context-aware. This persistent tuning prevents recurrence, reduces alert noise, and maintains security coverage for real threats.
- ✗
Mark the incident as 'False positive' and add a comment
Why it's wrong here
Marking the incident as 'False positive' and adding a comment documents your analyst reasoning and preserves audit trail, but it is entirely reactive and does not modify the analytics rule or its scheduling parameters. Unlike rule modification, this action does not suppress future alerts or adjust the detection logic, so the same benign activity will continue to trigger incidents. Comments and classifications serve triage and reporting, not prevention.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.