Microsoft Security Operations Analyst Associate SC-200 Practice Question
You are investigating an alert in Microsoft Defender for Cloud that reports a possible reverse-shell attempt on an Azure virtual machine. After reviewing the evidence, you confirm that the alert was raised by a trusted diagnostic script and is a known benign event. You need to prevent Microsoft Defender for Cloud from generating the same alert when the script runs on any other virtual machine in the subscription, but you must keep all other security detections active. Which action should you take directly from the alert's details blade to meet this requirement?
Disable the Microsoft Defender for Servers plan in the subscription.
Disable the security policy assignment that contains the reverse-shell analytic.
Create a suppression rule that targets this alert type for the subscription.
Add an exclusion tag to the virtual machine so Defender for Cloud ignores it.
From the alert details blade you can create an alert-suppression rule. A suppression rule lets you specify the alert type and a scope (such as subscription, resource group, or specific resource) so that identical alerts are automatically dismissed in the future. This stops only the chosen alert while leaving the Defender for Servers plan and all other alert types fully operational. Disabling the plan or turning off the entire policy would remove many other detections, and adding a custom tag is not recognized by Defender for Cloud as an exclusion mechanism.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Microsoft Defender for Cloud?
Open an interactive chat with Bash
What is a suppression rule in Microsoft Defender for Cloud?
Open an interactive chat with Bash
What is a reverse-shell attack?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .