ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 134 - SC-200 discussion

Report
Export

You have two Azure subscriptions that use Microsoft Defender for Cloud.

You need to ensure that specific Defender for Cloud security alerts are suppressed at the root management group level. The solution must minimize administrative effort.

What should you do in the Azure portal?

A.

Create an Azure Policy assignment.

Answers
A.

Create an Azure Policy assignment.

B.

Modify the Workload protections settings in Defender for Cloud.

Answers
B.

Modify the Workload protections settings in Defender for Cloud.

C.

Create an alert rule in Azure Monitor.

Answers
C.

Create an alert rule in Azure Monitor.

D.

Modify the alert settings in Defender for Cloud.

Answers
D.

Modify the alert settings in Defender for Cloud.

Suggested answer: D

Explanation:


You can use alerts suppression rules to suppress false positives or other unwanted security alerts from Defender for Cloud.

Note: To create a rule directly in the Azure portal:

1. From Defender for Cloud's security alerts page:

Select the specific alert you don't want to see anymore, and from the details pane, select Take action.

Or, select the suppression rules link at the top of the page, and from the suppression rules page select Create new suppression rule:

2. In the new suppression rule pane, enter the details of your new rule.

Your rule can dismiss the alert on all resources so you don't get any alerts like this one in the future.

Your rule can dismiss the alert on specific criteria - when it relates to a specific IP address, process name, user account, Azure resource, or location.

3. Enter details of the rule.

4. Save the rule.

Reference: https://docs.microsoft.com/en-us/azure/defender-for-cloud/alerts-suppression-rules

asked 05/10/2024
Mitesh Patel
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first