nerdexam
Microsoft

SC-200 · Question #160

Microsoft Defender for Endpoint gives configuration selections for alerts and detections. These include notifications, custom indicators, and detection rules. Which filter is a part of an Alert…

The correct answer is B. Alert Severity. When creating an alert notification rule in Microsoft Defender for Endpoint, the available filters include Alert Severity (Informational, Low, Medium, High) and Device Group. Alert Severity (B) lets you scope notifications so that only alerts meeting a certain severity…

Submitted by helene.fr· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Endpoint

Question

Microsoft Defender for Endpoint gives configuration selections for alerts and detections. These include notifications, custom indicators, and detection rules. Which filter is a part of an Alert notification rule?

Options

  • ASubject IDs
  • BAlert Severity
  • CAccount
  • DAlert IDs

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    87% (40)
  • C
    4% (2)
  • D
    7% (3)

Explanation

When creating an alert notification rule in Microsoft Defender for Endpoint, the available filters include Alert Severity (Informational, Low, Medium, High) and Device Group. Alert Severity (B) lets you scope notifications so that only alerts meeting a certain severity threshold trigger an email, reducing noise. Subject IDs, Account, and Alert IDs are not filter fields offered within the alert notification rule configuration UI. This is a common exam point because candidates may confuse notification rule filters with alert query filters used in hunting or advanced hunting scenarios.

Topics

#Microsoft Defender for Endpoint#Alerts#Notifications#Configuration

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice