SC-200 Practice Question 3783
Exam: SC-200
Domain: Respond to security incidents
Difficulty: easy
What is the purpose of configuring "Alert suppression rules" in Microsoft Defender XDR?
Answer Options
A
Automatically hides or resolves known benign alerts matching specific criteria
B
Deletes all incoming security alerts permanently
C
Disables real-time antivirus scanning across the company
D
Blocks all outbound email traffic from the tenant
Correct Answer
A: Automatically hides or resolves known benign alerts matching specific criteria
Explanation
Suppression rules automatically resolve or hide known benign alerts (false positives) based on specific criteria, keeping the active incident queue clean.