SC-200 · Question #108
You have an Azure subscription that contains a virtual machine named VM1 and uses Azure Defender. Azure Defender has automatic provisioning enabled. You need to create a custom alert suppression…
The correct answer is C. On VM1 trigger a PowerShell alert. For a rule to suppress an alert on a specific subscription, that alert type has to have been triggered at least once before the rule is created. https://docs.microsoft.com/en-us/azure/defender-for-cloud/alerts-suppression-rules#create-a- suppression-rule
Question
You have an Azure subscription that contains a virtual machine named VM1 and uses Azure Defender. Azure Defender has automatic provisioning enabled. You need to create a custom alert suppression rule that will supress false positive alerts for suspicious use of PowerShell on VM1. What should you do first?
Options
- AFrom Azure Security Center, add a workflow automation.
- BOn VM1, run the cmdlet.
- COn VM1 trigger a PowerShell alert.
- DFrom Azure Security Center, export the alerts to a Log Analytics workspace.
How the community answered
(34 responses)- A15% (5)
- B9% (3)
- C74% (25)
- D3% (1)
Explanation
For a rule to suppress an alert on a specific subscription, that alert type has to have been triggered at least once before the rule is created. https://docs.microsoft.com/en-us/azure/defender-for-cloud/alerts-suppression-rules#create-a- suppression-rule
Topics
Community Discussion
No community discussion yet for this question.