SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your company uses Microsoft Defender for Endpoint. A security analyst reports that a device is showing multiple alerts for the same malware variant, but the alerts are being automatically suppressed after the initial detection. What is the most likely reason for this behavior?
⚠ Common exam trap
Candidates often confuse alert suppression with automatic investigation and remediation, assuming that alerts are suppressed because they were already resolved, when in fact suppression is a separate noise-reduction mechanism that occurs before any remediation actions are taken.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Alert suppression is enabled to reduce noise from repeated detections
Microsoft Defender for Endpoint includes alert suppression as a built-in feature to reduce alert fatigue from repeated detections of the same malware variant on the same device. When the same file or behavior is detected multiple times, the system automatically suppresses subsequent alerts after the initial detection, consolidating them into a single incident. This behavior is controlled by suppression rules that are enabled by default for common malware patterns, ensuring security analysts are not overwhelmed by duplicate alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Alert suppression is enabled to reduce noise from repeated detections
Why this is correct
Microsoft Defender for Endpoint incorporates automatic alert suppression mechanisms designed to combat alert fatigue within security operations. When the system detects multiple instances of the exact same threat or activity on a device within a short timeframe, it intelligently suppresses subsequent duplicate alerts. This ensures security analysts can focus on unique, high-fidelity threats rather than being overwhelmed by redundant notifications, streamlining incident response.
- ✗
The alerts are classified as low severity
Why it's wrong here
Alert severity classification in Microsoft Defender for Endpoint primarily dictates prioritization for investigation and response, not automatic suppression. While low-severity alerts might be deprioritized, the system's alert suppression feature specifically targets duplicate detections regardless of their assigned severity level. A high-severity alert would still be suppressed if it's a repeated instance of an already acknowledged or handled threat, preventing notification overload.
- ✗
The device is not properly onboarded to Microsoft Defender for Endpoint
Why it's wrong here
If a device were not properly onboarded to Microsoft Defender for Endpoint, its security posture would not be monitored, and consequently, no alerts would be generated from that device whatsoever. The premise of alerts being generated and then *suppressed* inherently confirms that the device is actively reporting telemetry to Defender for Endpoint. Onboarding is a fundamental prerequisite for any detection and alerting capabilities to function.
- ✗
Automatic investigation and remediation resolved the alerts
Why it's wrong here
Automatic investigation and remediation in Defender for Endpoint work to neutralize threats and resolve security issues on affected devices. However, alert suppression is a distinct function focused on managing the volume of notifications by hiding duplicate alerts, independent of whether the underlying threat has been remediated. While remediation is the ultimate goal, suppression prevents redundant alerts from appearing in the portal, even if the remediation process is still ongoing or has just completed.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Alert fatigue
Alert fatigue is the desensitization and overwhelming feeling security analysts experience when they receive so many security alerts that they begin to ignore or miss them.
Key term
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise-grade security platform that protects devices, servers, and networks from advanced cyber threats by combining antivirus, endpoint detection and response, and automated investigation and remediation.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.