Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel and has enabled UEBA. You notice that many low-severity incidents are being created from high-volume informational alerts. You want to reduce noise without disabling data connectors. What should you do?

⚠ Common exam trap

Many exam-takers choose automation rules (Option A) because they seem like a quick fix to close incidents, but they fail to realize that the incidents are still created and consume resources, whereas modifying the query prevents generation entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the analytics rule query to exclude the high-volume informational events using KQL.

Modifying the analytics rule query to exclude high-volume informational events using KQL directly addresses the root cause: the rule is generating low-severity incidents from noisy informational data. This approach preserves the data connectors and UEBA functionality while filtering out the specific events that cause alert fatigue. Unlike automation rules that close incidents after creation, query modification prevents the incidents from being generated in the first place.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an automation rule that closes low-severity incidents immediately.

    Why it's wrong here

    An automation rule is a response mechanism that executes only after an incident has already been created and triaged into Sentinel. It does nothing to prevent the high-volume informational events from generating alerts, consuming storage, and triggering playbook runs. Auto-closing low-severity incidents can also suppress analytics data, mask underlying adversarial behavior, and skew SOC metrics, so it is not a noise-reduction strategy.

  • ✗

    Increase the incident creation threshold in the analytics rule.

    Why it's wrong here

    Sentinel scheduled analytics rules do not expose a numeric incident-creation threshold property that can be increased; alert generation is determined by the query results and the rule's frequency/period. Even if a threshold were implemented, applying it uniformly would fail to separate high-volume informational events from genuinely suspicious activity. Noise suppression at the rule level must be done in the query itself, such as using `where` clauses, not by changing a nonexistent threshold.

  • ✓

    Modify the analytics rule query to exclude the high-volume informational events using KQL.

    Why this is correct

    Modify the KQL query behind the analytics rule to exclude the high-volume informational events, e.g., by filtering out event IDs, specific log sources, or task categories with a `where` clause. This stops those events from ever being selected for alert generation, reducing incident noise and storage/ingestion costs at the source. It preserves detection coverage for all other event types and is the recommended approach for tuning noisy analytics rules.

  • ✗

    Disable the Microsoft 365 Defender connector for those data sources.

    Why it's wrong here

    Disabling the Microsoft 365 Defender connector is an all-or-nothing action that halts ingestion of every data source routed through that connector, not just the informational events causing noise. This would break downstream analytics rules, UEBA learning, and threat-hunting queries that rely on legitimate telemetry from the same connector. A targeted KQL filter in the analytics rule or a data collection rule is far more surgical and keeps operational data flowing.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.