Microsoft Security Operations Analyst Associate SC-200 Practice Question

You need to reduce alert fatigue in Microsoft 365 Defender by preventing repeat alerts that are triggered by the same user account within a short period. An existing alert titled "Suspicious PowerShell activity" is generating multiple alerts for the same user in quick succession. You decide to configure alert suppression directly from one of the alert instances. Which suppression configuration will ensure that any alert with the same title raised for that user account is automatically suppressed if it occurs within the next 24 hours, while still allowing alerts with the same title for other users to appear?

  • Create an alert suppression rule that matches on Device and set the suppression scope to This device only with a time range of 24 hours.

  • Create an alert suppression rule that matches on Any entity and set the suppression scope to All entities with a Permanent time range.

  • Create an alert suppression rule that matches on the User entity and set the suppression scope to This user only with a time range of 24 hours.

  • Edit the underlying detection rule and clear the Create alert option so no alerts are generated for this detection.

Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot