-
SC-200 Review test Set 3 – question 22 (Manage Security Threats)
-
Hi! 🖐🏻
In this question, the highlighted right answers don’t match the explanation below 🔎
Which ones are the actual good answers ? 🤔
Also, why should we create a suppression rule if we are explicitly told to not to keep intact the security posture regarding these macros?
Thank you in advance for your help! 🙏🏻
Valentin
-
Hi Valentin,
Thank you for reaching out and for taking the time to flag this. We really appreciate your attention to detail!
You are absolutely right, the answers highlighted in the screenshot do not match the correct ones in the solution text. We have already fixed this, and the changes will be reflected on the portal shortly.
To confirm, the three correct answers for this question are:
– Hide the alert from the list
– Create a suppression rule for a specific device group
– Set up a new alert
Regarding your question about the suppression rule, the key is the scope. When you create a suppression rule for a specific device group, it only applies to the finance department devices, leaving the rest of the organization’s security coverage untouched. Creating it for any asset would be too broad and could silence legitimate alerts on other machines, which is exactly what the question warns against. So scoping it to a device group is what keeps the security posture intact.
We hope that clears things up! Let us know if you have any other questions
Best regards,
Irene @ Tutorials Dojo
-
Thank you Irene for the clarification.
Why creating a new alert when one already exists though?
This question is really confusing.
-
This reply was modified 2 months, 3 weeks ago by
vnapoli.
-
Hi Valentin,
Great question! “Generate the alert” does not mean creating a duplicate of the existing alert manually.
Accordingly, when a suppression rule hides a false positive, the system does not ignore that activity permanently. If the Automated Investigation and Response (AIR) engine later detects that the same activity is actually malicious, it will automatically reactivate and generate a new alert.
In other words, suppressing the false positive does not turn off detection; it just filters out the known noise. The security posture stays intact because a new alert will still be raised if the macro activity ever becomes a genuine threat.
Hope that clears it up! Let us know if you have further questions.
Best regards,
Irene @ Tutorials Dojo
-
Thank you Irene for your help 🙏🏻
I am deeply sorry to write again in this thread as I have the sensation to ask for the same thing again but the question asks what are the ACTIONS we are supposed to do, however if I understand correctly we do not have to “set up a new alert” manually as it is just an automatic behavior of AIR IF a malicious activity related to this rule is detected.
So how “set up a new alert” is a correct answer to the question “what actions should you do” if we are not actually setting up a new alert and just letting AIR do its work.
-
-
This reply was modified 2 months, 3 weeks ago by
Log in to reply.