SC-200 · Question #160
Microsoft Defender for Endpoint gives configuration selections for alerts and detections. These include notifications, custom indicators, and detection rules. Which filter is a part of an Alert…
The correct answer is B. Alert Severity. When creating an alert notification rule in Microsoft Defender for Endpoint, the available filters include Alert Severity (Informational, Low, Medium, High) and Device Group. Alert Severity (B) lets you scope notifications so that only alerts meeting a certain severity…
Question
Microsoft Defender for Endpoint gives configuration selections for alerts and detections. These include notifications, custom indicators, and detection rules. Which filter is a part of an Alert notification rule?
Options
- ASubject IDs
- BAlert Severity
- CAccount
- DAlert IDs
How the community answered
(46 responses)- A2% (1)
- B87% (40)
- C4% (2)
- D7% (3)
Explanation
When creating an alert notification rule in Microsoft Defender for Endpoint, the available filters include Alert Severity (Informational, Low, Medium, High) and Device Group. Alert Severity (B) lets you scope notifications so that only alerts meeting a certain severity threshold trigger an email, reducing noise. Subject IDs, Account, and Alert IDs are not filter fields offered within the alert notification rule configuration UI. This is a common exam point because candidates may confuse notification rule filters with alert query filters used in hunting or advanced hunting scenarios.
Topics
Community Discussion
No community discussion yet for this question.