SC-200 Practice Question 3814
Exam: SC-200
Domain: Respond to security incidents
Difficulty: medium
You are closing an incident in Microsoft Defender XDR. You want to ensure that similar future alerts generated by the same automated vulnerability scan IP are classified as benign automatically. What should you create upon closing?
Answer Options
A
An Alert Suppression and Tuning Rule
B
A static DNS record
C
A Group Policy Object
D
An Exchange message forwarding rule
Correct Answer
A: An Alert Suppression and Tuning Rule
Explanation
Create an Alert Suppression and Tuning Rule directly from the incident closure dialog to suppress future matches matching that specific entity criteria.