SC-200 Practice Question 3814

Exam: SC-200
Domain: Respond to security incidents
Difficulty: medium
You are closing an incident in Microsoft Defender XDR. You want to ensure that similar future alerts generated by the same automated vulnerability scan IP are classified as benign automatically. What should you create upon closing?

Answer Options

A
An Alert Suppression and Tuning Rule
B
A static DNS record
C
A Group Policy Object
D
An Exchange message forwarding rule

Correct Answer

A: An Alert Suppression and Tuning Rule

Explanation

Create an Alert Suppression and Tuning Rule directly from the incident closure dialog to suppress future matches matching that specific entity criteria.
SC-200 Practice Question 3814 – Respond to security incidents