Microsoft Security Operations Analyst Associate SC-200 Practice Question

You investigate a Sensitive group membership change alert raised by Microsoft Defender for Identity (MDI) on one of your domain controllers. After validating the change, you confirm that the activity was authorized and you want to prevent MDI from raising the same alert again when the same user adds members to the same group, while still keeping the detection active for all other users and groups. In the Microsoft 365 Defender portal, which action should you take on the alert to meet this requirement?

  • Set the alert status to Resolved so that identical future alerts are automatically ignored.

  • Isolate the domain controller that generated the alert by using Microsoft Defender for Endpoint.

  • Disable the Sensitive group membership change detection in the Defender for Identity settings.

  • Choose Suppress similar alerts and create a suppression rule scoped to the user and group involved.

Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot