Ends in
00
days
00
hrs
00
mins
00
secs
SHOP NOW

🚀 $4.99 Claude Certified Architect Foundations CCA-F Practice Exams

Find answers, ask questions, and connect with our
community around the world.

Home Forums Azure SC-200 Review test Set 3 – question 22 (Manage Security Threats) Reply To: SC-200 Review test Set 3 – question 22 (Manage Security Threats)

  • Irene-TutorialsDojo

    Administrator
    April 15, 2026 at 1:01 pm

    Hi Valentin,

    Great question! “Generate the alert” does not mean creating a duplicate of the existing alert manually.

    Accordingly, when a suppression rule hides a false positive, the system does not ignore that activity permanently. If the Automated Investigation and Response (AIR) engine later detects that the same activity is actually malicious, it will automatically reactivate and generate a new alert.

    In other words, suppressing the false positive does not turn off detection; it just filters out the known noise. The security posture stays intact because a new alert will still be raised if the macro activity ever becomes a genuine threat.

    Reference: https://learn.microsoft.com/en-us/defender-xdr/investigate-alerts?tabs=settings#built-in-alert-tuning-rules

    Hope that clears it up! Let us know if you have further questions.

    Best regards,

    Irene @ Tutorials Dojo

Skip to content