Courseiva

SC-200 Manage a security operations environment Practice Question

Your security team receives frequent false positive alerts from Microsoft Defender for Cloud Apps. You need to reduce noise without disabling any threat detection policies. What should you do?

⚠ Common exam trap

Test-takers frequently confuse 'suppression' with 'disabling' or 'tuning' policies, assuming that reducing noise requires altering detection logic or severity, rather than using the dedicated suppression feature that automatically dismisses matching alerts without affecting detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure suppression rules based on user, IP, or app to automatically dismiss matching alerts.

Suppression rules in Microsoft Defender for Cloud Apps allow you to automatically dismiss alerts that match specific criteria (e.g., user, IP address, or app) without disabling the underlying threat detection policy. This reduces false positive noise while keeping the detection engine active for genuine threats. Disabling policies or adjusting severity thresholds would either remove detection entirely or fail to address the root cause of false positives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the built-in anomaly detection policies that generate false positives.

    Why it's wrong here

    Disabling built-in anomaly detection policies is a blunt instrument that removes the underlying detection logic entirely, not just the noisy results. Once disabled, Defender for Cloud Apps (or the relevant Microsoft 365 Defender workload) will stop generating those alerts for everyone, which means genuinely malicious anomalous behavior will also go undetected. The goal is to reduce false-positive volume while preserving detection coverage; suppression rules achieve that by dismissing matching alerts at the triage layer without altering the policy's detection state.

  • ✓

    Configure suppression rules based on user, IP, or app to automatically dismiss matching alerts.

    Why this is correct

    Suppression rules are the correct approach because they operate at the alert-dismissal stage rather than the detection stage. In Microsoft Defender for Cloud Apps, you can define suppression based on entity attributes such as user, IP address, or app, so alerts that match the rule are automatically closed or hidden before they reach the analyst. This directly addresses false positives by removing known-benign patterns (e.g., a service account that legitimately performs anomalous-looking bulk downloads) while keeping the underlying policy active for genuinely suspicious activity. Crucially, this does not weaken detection coverage and is fully auditable, making it the recommended operational response to alert fatigue.

  • ✗

    Adjust the alert severity thresholds in the policy settings.

    Why it's wrong here

    Adjusting alert severity thresholds in the policy settings is ineffective because severity is a classification label, not a volume-control mechanism. In Defender for Cloud Apps, severity can be set to Low, Medium, or High, but changing it from High to Medium does not prevent the alert from being created; the same alert will simply appear with a different urgency in the alert queue. If anything, every alert still gets generated and must be reviewed, so the false-positive load remains identical—you've only changed how prominently it's displayed. Suppression is the mechanism designed to actually remove matching alerts from the review queue.

  • ✗

    Create custom detection policies to override default rules.

    Why it's wrong here

    Creating custom detection policies to override default rules will not reduce false positives and will typically add more noise. Custom policies in Microsoft Defender for Cloud Apps are additional detection logic layered on top of the built-in ones; they are not a substitute or an override for native rules. Unless you also disable or suppress the original default policies, both the built-in alerts and your new custom alerts will fire, increasing the total alert volume. The correct path is to suppress the unwanted alerts from the existing policy, not to build parallel detections that compound the problem.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.