Find answers, ask questions, and connect with our
community around the world.

Home Forums Azure SC-200 Review test Set 3 – question 22 (Manage Security Threats)

  • SC-200 Review test Set 3 – question 22 (Manage Security Threats)

     vnapoli updated 2 months, 3 weeks ago 2 Members · 5 Posts
  • vnapoli

    Member
    April 13, 2026 at 10:44 pm

    Hi! 🖐🏻

    In this question, the highlighted right answers don’t match the explanation below 🔎

    Which ones are the actual good answers ? 🤔

    Also, why should we create a suppression rule if we are explicitly told to not to keep intact the security posture regarding these macros?

    Thank you in advance for your help! 🙏🏻

    Valentin

  • Irene-TutorialsDojo

    Administrator
    April 14, 2026 at 1:28 pm

    Hi Valentin,

    Thank you for reaching out and for taking the time to flag this. We really appreciate your attention to detail!

    You are absolutely right, the answers highlighted in the screenshot do not match the correct ones in the solution text. We have already fixed this, and the changes will be reflected on the portal shortly.

    To confirm, the three correct answers for this question are:

    – Hide the alert from the list

    – Create a suppression rule for a specific device group

    – Set up a new alert

    Regarding your question about the suppression rule, the key is the scope. When you create a suppression rule for a specific device group, it only applies to the finance department devices, leaving the rest of the organization’s security coverage untouched. Creating it for any asset would be too broad and could silence legitimate alerts on other machines, which is exactly what the question warns against. So scoping it to a device group is what keeps the security posture intact.

    We hope that clears things up! Let us know if you have any other questions

    Best regards,

    Irene @ Tutorials Dojo

  • vnapoli

    Member
    April 14, 2026 at 5:54 pm

    Thank you Irene for the clarification.

    Why creating a new alert when one already exists though?

    This question is really confusing.

    • This reply was modified 2 months, 3 weeks ago by  vnapoli.
    • Irene-TutorialsDojo

      Administrator
      April 15, 2026 at 1:01 pm

      Hi Valentin,

      Great question! “Generate the alert” does not mean creating a duplicate of the existing alert manually.

      Accordingly, when a suppression rule hides a false positive, the system does not ignore that activity permanently. If the Automated Investigation and Response (AIR) engine later detects that the same activity is actually malicious, it will automatically reactivate and generate a new alert.

      In other words, suppressing the false positive does not turn off detection; it just filters out the known noise. The security posture stays intact because a new alert will still be raised if the macro activity ever becomes a genuine threat.

      Reference: https://learn.microsoft.com/en-us/defender-xdr/investigate-alerts?tabs=settings#built-in-alert-tuning-rules

      Hope that clears it up! Let us know if you have further questions.

      Best regards,

      Irene @ Tutorials Dojo

      • vnapoli

        Member
        April 17, 2026 at 5:12 pm

        Thank you Irene for your help 🙏🏻

        I am deeply sorry to write again in this thread as I have the sensation to ask for the same thing again but the question asks what are the ACTIONS we are supposed to do, however if I understand correctly we do not have to “set up a new alert” manually as it is just an automatic behavior of AIR IF a malicious activity related to this rule is detected.

        So how “set up a new alert” is a correct answer to the question “what actions should you do” if we are not actually setting up a new alert and just letting AIR do its work.

Viewing 1 - 3 of 3 replies

Log in to reply.

Original Post
0 of 0 posts June 2018
Now
Skip to content