Microsoft Security Operations Analyst Associate SC-200 Practice Question
You need to reduce noise from a benign line-of-business (LOB) utility that repeatedly triggers the built-in alert "Possible credential theft with lsass.exe" in Microsoft Defender XDR. The utility always runs from the folder C:\Program Files\Contoso\Tools. You create an alert suppression rule from one of the existing alerts. Which suppression scope should you choose to ensure that only future alerts that involve lsass.exe running from that specific folder on any device are hidden, while the same alert from other file paths is still generated?
When you create a suppression rule in Microsoft Defender XDR, you can scope it by alert title only, by alert title and entities, or by specific devices/users. Selecting the "alert title and entities" scope lets you add entity conditions-such as the file path of lsass.exe-to the rule. This hides future alerts only when the alert name and the specified entity values match (here, the full file path), so the benign LOB utility is suppressed everywhere, but genuine occurrences of the same alert from other paths continue to raise alerts. Scoping by alert title alone would silence every instance of that alert, while scoping by device or user would fail to cover all machines where the LOB utility runs.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an alert suppression rule in Microsoft Defender XDR?
Open an interactive chat with Bash
What does 'entities' mean in the context of alert suppression rules?
Open an interactive chat with Bash
Why suppress alerts by alert title and entities instead of other scopes?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .