nerdexam
Microsoft

SC-200 · Question #131

You have a Microsoft Sentinel workspace. You receive multiple alerts for failed sign-in attempts to an account. You identify that the alerts are false positives. You need to prevent additional…

The correct answer is A. Create an automation rule. Two methods for avoiding false positives: Automation rules create exceptions without modifying analytics rules. Scheduled analytics rules modifications permit more detailed and permanent exceptions. https://learn.microsoft.com/en-us/azure/sentinel/false-positives

Submitted by eva_at· Apr 18, 2026Detect and remediate threats using Microsoft Sentinel

Question

You have a Microsoft Sentinel workspace. You receive multiple alerts for failed sign-in attempts to an account. You identify that the alerts are false positives. You need to prevent additional failed sign-in alerts from being generated for the account. The solution must meet the following requirements:

  • Ensure that failed sign-in alerts are generated for other accounts.
  • Minimize administrative effort

What should do?

Options

  • ACreate an automation rule.
  • BCreate a watchlist.
  • CModify the analytics rule.
  • DAdd an activity template to the entity behavior.

How the community answered

(69 responses)
  • A
    75% (52)
  • B
    3% (2)
  • C
    6% (4)
  • D
    16% (11)

Explanation

Two methods for avoiding false positives: Automation rules create exceptions without modifying analytics rules. Scheduled analytics rules modifications permit more detailed and permanent exceptions. https://learn.microsoft.com/en-us/azure/sentinel/false-positives

Topics

#Microsoft Sentinel#Automation Rules#Alert Management#False Positives

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice