nerdexam
Microsoft

SC-200 · Question #14

Your company uses Microsoft Defender for Endpoint. The company has Microsoft Word documents that contain macros. The documents are used frequently on the devices of the company's accounting team…

The correct answer is B. Hide the alert. D. Create a suppression rule scoped to a device group. E. Generate the alert. To suppress a known false positive in Microsoft Defender for Endpoint while maintaining security posture, three coordinated steps are needed. First, you must be able to reproduce or generate the alert (E) so you have an instance to work with and create a suppression rule from…

Submitted by saadiq_pk· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Endpoint

Question

Your company uses Microsoft Defender for Endpoint. The company has Microsoft Word documents that contain macros. The documents are used frequently on the devices of the company's accounting team. You need to hide false positive in the Alerts queue, while maintaining the existing security posture. Which three actions should you perform?Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AResolve the alert automatically.
  • BHide the alert.
  • CCreate a suppression rule scoped to any device.
  • DCreate a suppression rule scoped to a device group.
  • EGenerate the alert.

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    83% (25)
  • C
    10% (3)

Explanation

To suppress a known false positive in Microsoft Defender for Endpoint while maintaining security posture, three coordinated steps are needed. First, you must be able to reproduce or generate the alert (E) so you have an instance to work with and create a suppression rule from. Then you hide the alert (B) to remove it from the active Alerts queue. Finally, you create a suppression rule scoped to a device group (D) - specifically the accounting team's device group - so the suppression only applies where the macro usage is legitimate, preserving alerts on all other devices. Option A (auto-resolve) is too blunt. Option C (scope to any device) would suppress the alert organization-wide, reducing the overall security posture - which the question explicitly prohibits.

Topics

#Defender for Endpoint#False Positives#Alert Management#Suppression Rules

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice