Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel. An incident has been identified as a false positive. What is the recommended action to prevent similar false positives in the future?

⚠ Common exam trap

Test-takers frequently confuse incident management actions (closing/classifying) with rule optimization, assuming that marking an incident as false positive automatically suppresses future similar alerts, when in fact it only affects the current incident's audit trail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the analytics rule to reduce false positives

Modifying the analytics rule addresses the root cause of the false positive by adjusting the rule's query logic, thresholds, or entity mappings to reduce noise. In Microsoft Sentinel, analytics rules define the conditions that generate incidents; tuning these rules (e.g., changing frequency, lookback period, or adding exclusion filters) directly prevents similar false positives from recurring. Simply closing or classifying incidents does not prevent future occurrences, and deleting the rule would remove all detection capability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete the analytics rule

    Why it's wrong here

    Deleting the analytics rule removes the detection logic entirely, which suppresses all future alerts generated by that rule and significantly broadens the security coverage gap. While it eliminates the noise, it also risks missing genuine malicious activity that shares similar patterns with the false positives. The better approach is to preserve the rule and tune its query, thresholds, or filters to balance detection fidelity with alert fatigue.

  • ✗

    Close the incident and set the classification to 'False positive'

    Why it's wrong here

    Closing the incident and setting the classification to 'False positive' only updates the incident's metadata in Microsoft Sentinel; it has no direct effect on the analytics rule that generated it. The classification is stored for audit and reporting purposes but does not automatically feed back into rule tuning or suppression logic. Future occurrences will still trigger the same alert, so this action is purely reactive and does not address the underlying detection configuration.

  • ✓

    Modify the analytics rule to reduce false positives

    Why this is correct

    Modifying the analytics rule is the correct action because it directly addresses the root cause of the false positives by adjusting the rule's query logic, threshold, or entity-specific filters. For example, you can add exclusions for known benign IP addresses, increase the aggregation window count, or refine the KQL query to be more context-aware. This persistent tuning prevents recurrence, reduces alert noise, and maintains security coverage for real threats.

  • ✗

    Mark the incident as 'False positive' and add a comment

    Why it's wrong here

    Marking the incident as 'False positive' and adding a comment documents your analyst reasoning and preserves audit trail, but it is entirely reactive and does not modify the analytics rule or its scheduling parameters. Unlike rule modification, this action does not suppress future alerts or adjust the detection logic, so the same benign activity will continue to trigger incidents. Comments and classifications serve triage and reporting, not prevention.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.