nerdexam
Microsoft

SC-200 · Question #158

Multiple false positive alerts are generating in a company XYZ. A security operations analyst working for XYZ needs to exclude an executable file to reduce alerts - c:\myxyzapp\myxyzwinapp.exe…

The correct answer is C. File. File will exclude only this specific file, whereas extension would exclude all files with the extensions, and folder would exclude all files in a folder. Registry exclusion doesn't happen…

Submitted by kim_seoul· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Endpoint

Question

Multiple false positive alerts are generating in a company XYZ. A security operations analyst working for XYZ needs to exclude an executable file to reduce alerts - c:\myxyzapp\myxyzwinapp.exe, which exclusion type must they use?

Options

  • AExtension
  • BFolder
  • CFile
  • DRegistry

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    80% (28)
  • D
    11% (4)

Explanation

File will exclude only this specific file, whereas extension would exclude all files with the extensions, and folder would exclude all files in a folder. Registry exclusion doesn't happen. https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-extension- file-exclusions-microsoft-defender-antivirus?view=o365-worldwide

Topics

#Exclusions#False positives#Endpoint security#Alert management

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice