exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 42 discussion

Actual exam question from Microsoft's SC-200
Question #: 42
Topic #: 3
[All SC-200 Questions]

You have two Azure subscriptions that use Microsoft Defender for Cloud.
You need to ensure that specific Defender for Cloud security alerts are suppressed at the root management group level. The solution must minimize administrative effort.
What should you do in the Azure portal?

  • A. Create an Azure Policy assignment.
  • B. Modify the Workload protections settings in Defender for Cloud.
  • C. Create an alert rule in Azure Monitor.
  • D. Modify the alert settings in Defender for Cloud.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
siddique12345
Highly Voted 2 years, 1 month ago
Selected Answer: A
To suppress alerts at the management group level, use Azure Policy
upvoted 20 times
Xyz_40
2 years ago
Right and correct
upvoted 2 times
AMZ
1 year, 12 months ago
Tricky question, I think A is correct. - creating a suppression rule is not one of the options
upvoted 2 times
...
...
...
RomanV
Highly Voted 1 year, 12 months ago
Selected Answer: A
"To suppress alerts at the management group level, use Azure Policy" https://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-suppression-rules#create-a-suppression-rule
upvoted 9 times
...
chepeerick
Most Recent 12 months ago
Option
upvoted 1 times
...
testypesty
1 year, 4 months ago
Selected Answer: A
You can apply suppression rules to management groups or to subscriptions. To suppress alerts for a management group, use Azure Policy. https://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-suppression-rules
upvoted 3 times
...
D_PaW
1 year, 4 months ago
Selected Answer: A
To minimize effort I would go with A, set it once, forget it and keep it enforced. A - Can set it at Management Group level B - Nothing to do alert suppression C - Generate an alert, will not suppress another D - You can suppress an alert, but not at Management Group or Subscription level Looking at the Policy Definitions: Suppress Azure Security Center alerts to reduce alerts fatigue by deploying suppression rules on your management group or subscription. https://learn.microsoft.com/en-us/azure/defender-for-cloud/policy-reference
upvoted 4 times
Ramye
7 months, 4 weeks ago
Thx for sharing and confirming.
upvoted 1 times
...
...
Danford25
1 year, 5 months ago
Answer is A https://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-suppression-rules
upvoted 2 times
Ramye
7 months, 4 weeks ago
Thx for sharing, however, the below link is more relevant for this specific question. https://learn.microsoft.com/en-us/azure/defender-for-cloud/policy-reference
upvoted 1 times
...
...
therealletsgo
1 year, 6 months ago
Selected Answer: D
"Modifying alert settings" on the Security Alerts Page in Defender for cloud includes the option to create suppression rules. https://learn.microsoft.com/en-us/azure/defender-for-cloud/managing-and-responding-alerts
upvoted 2 times
...
[Removed]
1 year, 8 months ago
Selected Answer: A
A. Create an Azure Policy assignment. By creating an Azure Policy assignment at the root management group level, you can define a policy to suppress specific Defender for Cloud security alerts. This allows you to ensure that the policy applies to all subscriptions and resources under the management group, without the need to modify the settings for each individual subscription.
upvoted 2 times
...
[Removed]
1 year, 8 months ago
I could see it being either A or D depending if they are only going to have 2 subscriptions or add more in the future. Should we assume that they are never adding anymore than the 2 they already have?
upvoted 1 times
...
eddz25
1 year, 9 months ago
Selected Answer: A
A. Create an Azure Policy assignment. To suppress specific Defender for Cloud security alerts at the root management group level, you can create an Azure Policy assignment. This will allow you to apply a policy that will suppress the alerts across all subscriptions and management groups in the tenant. Azure Policy allows you to define and assign policies that govern your resources and enforce compliance. By creating an Azure Policy assignment, you can set up the suppression of alerts in one place, minimizing administrative effort.
upvoted 3 times
...
Apocalypse03
1 year, 10 months ago
Selected Answer: A
To ensure that specific Defender for Cloud security alerts are suppressed at the root management group level, you should create an Azure Policy assignment.
upvoted 4 times
...
amsioso
2 years, 1 month ago
https://docs.microsoft.com/en-us/azure/defender-for-cloud/alerts-suppression-rules#create-a-suppression-rule https://learn.microsoft.com/en-us/azure/governance/policy/overview#assignments https://www.red-gate.com/simple-talk/cloud/azure/azure-policies-and-management-groups/ Think the answer is correct; D. Because is the one with minimize administrative effort as you can see here: https://learn.microsoft.com/en-us/answers/questions/8713/what-is-the-min-iam-role-required-to-create-azure.html https://learn.microsoft.com/en-us/azure/defender-for-cloud/permissions#roles-and-allowed-actions
upvoted 1 times
extopic01
2 years ago
from your link: https://docs.microsoft.com/en-us/azure/defender-for-cloud/alerts-suppression-rules#create-a-suppression-rule it says: To suppress alerts at the management group level, use Azure Policy. answer is A
upvoted 3 times
...
...
Fukacz
2 years, 1 month ago
Selected Answer: D
D is correct. When making a suppression you can select one, multiple or all subscriptions.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago