Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your company uses Microsoft Defender for Endpoint. A security analyst reports that a device is showing multiple alerts for the same malware variant, but the alerts are being automatically suppressed after the initial detection. What is the most likely reason for this behavior?

⚠ Common exam trap

Candidates often confuse alert suppression with automatic investigation and remediation, assuming that alerts are suppressed because they were already resolved, when in fact suppression is a separate noise-reduction mechanism that occurs before any remediation actions are taken.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Alert suppression is enabled to reduce noise from repeated detections

Microsoft Defender for Endpoint includes alert suppression as a built-in feature to reduce alert fatigue from repeated detections of the same malware variant on the same device. When the same file or behavior is detected multiple times, the system automatically suppresses subsequent alerts after the initial detection, consolidating them into a single incident. This behavior is controlled by suppression rules that are enabled by default for common malware patterns, ensuring security analysts are not overwhelmed by duplicate alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Alert suppression is enabled to reduce noise from repeated detections

    Why this is correct

    Microsoft Defender for Endpoint incorporates automatic alert suppression mechanisms designed to combat alert fatigue within security operations. When the system detects multiple instances of the exact same threat or activity on a device within a short timeframe, it intelligently suppresses subsequent duplicate alerts. This ensures security analysts can focus on unique, high-fidelity threats rather than being overwhelmed by redundant notifications, streamlining incident response.

  • The alerts are classified as low severity

    Why it's wrong here

    Alert severity classification in Microsoft Defender for Endpoint primarily dictates prioritization for investigation and response, not automatic suppression. While low-severity alerts might be deprioritized, the system's alert suppression feature specifically targets duplicate detections regardless of their assigned severity level. A high-severity alert would still be suppressed if it's a repeated instance of an already acknowledged or handled threat, preventing notification overload.

  • The device is not properly onboarded to Microsoft Defender for Endpoint

    Why it's wrong here

    If a device were not properly onboarded to Microsoft Defender for Endpoint, its security posture would not be monitored, and consequently, no alerts would be generated from that device whatsoever. The premise of alerts being generated and then *suppressed* inherently confirms that the device is actively reporting telemetry to Defender for Endpoint. Onboarding is a fundamental prerequisite for any detection and alerting capabilities to function.

  • Automatic investigation and remediation resolved the alerts

    Why it's wrong here

    Automatic investigation and remediation in Defender for Endpoint work to neutralize threats and resolve security issues on affected devices. However, alert suppression is a distinct function focused on managing the volume of notifications by hiding duplicate alerts, independent of whether the underlying threat has been remediated. While remediation is the ultimate goal, suppression prevents redundant alerts from appearing in the portal, even if the remediation process is still ongoing or has just completed.

Go deeper

Related to this question

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.