Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CSCP All Questions

View all questions & answers for the CSCP exam

Exam SC-200 topic 2 question 27 discussion

Actual exam question from APICS's CSCP
Question #: 27
Topic #: 1
[All CSCP Questions]

You have an Azure subscription that contains a virtual machine named VM1 and uses Azure Defender. Azure Defender has automatic provisioning enabled.
You need to create a custom alert suppression rule that will supress false positive alerts for suspicious use of PowerShell on VM1.
What should you do first?

  • A. From Azure Security Center, add a workflow automation.
  • B. On VM1, run the Get-MPThreatCatalog cmdlet.
  • C. On VM1 trigger a PowerShell alert.
  • D. From Azure Security Center, export the alerts to a Log Analytics workspace.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Lion007
Highly Voted 2 years, 5 months ago
Correct asnswer. Microsoft docs say: "For a rule to suppress an alert on a specific subscription, that alert type has to have been triggered at least once before the rule is created." https://docs.microsoft.com/en-us/azure/defender-for-cloud/alerts-suppression-rules#create-a-suppression-rule
upvoted 30 times
Gurulee
1 year, 1 month ago
Agreed, thank you for the confirming.
upvoted 1 times
...
...
Mthaher
Highly Voted 2 years, 7 months ago
Correct , you need to generate the alert , then create the suppression rule https://docs.microsoft.com/en-us/azure/defender-for-cloud/alerts-suppression-rules#what-are-suppression-rules
upvoted 6 times
...
chepeerick
Most Recent 1 year, 1 month ago
Correct
upvoted 2 times
...
mali1969
1 year, 3 months ago
Selected Answer: C
C. On VM1 trigger a PowerShell alert. This will allow you to create a custom alert suppression rule based on the specific alert that you want to suppress. To trigger a PowerShell alert on VM1, you can follow these steps: On VM1, open PowerShell and run the following command: Invoke-WebRequest -Uri https://aka.ms/createalert Wait for a few minutes until the alert is generated in Azure Security Center. Go to Security Center in the Azure portal and select Security alerts. Find the alert with the title “Suspicious use of PowerShell” and the resource name “VM1”. Click on the alert to open its details pane.
upvoted 2 times
...
mimguy
1 year, 4 months ago
On the exam July 7 2023
upvoted 3 times
...
imhere4you
1 year, 5 months ago
On exam - 19 June 2023
upvoted 4 times
...
exmITQS
1 year, 9 months ago
Selected Answer: C
Before creating a custom alert suppression rule that will supress false positive alerts for suspicious use of PowerShell on VM1, you need to trigger the suspicious use of PowerShell alert on VM1. So the correct answer is C. On VM1 trigger a PowerShell alert.
upvoted 1 times
...
jrjrjrchlv
1 year, 10 months ago
Selected Answer: C
You should first C. trigger a PowerShell alert on VM1 to create a custom alert suppression rule that will suppress false positive alerts for suspicious use of PowerShell on VM1. After triggering the alert, you can use the information provided in the alert to create a suppression rule that will prevent similar alerts from being generated in the future.
upvoted 2 times
Lone__Wolf
1 year, 9 months ago
Yep yep!
upvoted 1 times
...
...
Fukacz
2 years, 2 months ago
Selected Answer: C
First you need an alert
upvoted 3 times
...
sainfosec
2 years, 3 months ago
Selected Answer: C
C for correct
upvoted 2 times
...
vnez
2 years, 3 months ago
Selected Answer: C
Correct!
upvoted 2 times
...
CatoFong
2 years, 4 months ago
Selected Answer: C
C is correct. Documentation provided by Lion007 and Mthaher
upvoted 3 times
...
sadako
2 years, 7 months ago
Selected Answer: A
Should be A
upvoted 3 times
j888
2 years, 7 months ago
I think C is correct. You will need an alert for this specific trigger and then you will be able to suppress it. A is for automation response not supression.
upvoted 5 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...