nerdexam
Microsoft

SC-200 · Question #108

You have an Azure subscription that contains a virtual machine named VM1 and uses Azure Defender. Azure Defender has automatic provisioning enabled. You need to create a custom alert suppression…

The correct answer is C. On VM1 trigger a PowerShell alert. For a rule to suppress an alert on a specific subscription, that alert type has to have been triggered at least once before the rule is created. https://docs.microsoft.com/en-us/azure/defender-for-cloud/alerts-suppression-rules#create-a- suppression-rule

Submitted by amina.ke· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Cloud

Question

You have an Azure subscription that contains a virtual machine named VM1 and uses Azure Defender. Azure Defender has automatic provisioning enabled. You need to create a custom alert suppression rule that will supress false positive alerts for suspicious use of PowerShell on VM1. What should you do first?

Options

  • AFrom Azure Security Center, add a workflow automation.
  • BOn VM1, run the cmdlet.
  • COn VM1 trigger a PowerShell alert.
  • DFrom Azure Security Center, export the alerts to a Log Analytics workspace.

How the community answered

(34 responses)
  • A
    15% (5)
  • B
    9% (3)
  • C
    74% (25)
  • D
    3% (1)

Explanation

For a rule to suppress an alert on a specific subscription, that alert type has to have been triggered at least once before the rule is created. https://docs.microsoft.com/en-us/azure/defender-for-cloud/alerts-suppression-rules#create-a- suppression-rule

Topics

#Alert Suppression#Microsoft Defender for Cloud#False Positives#Alert Management

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice