Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRHard
A security analyst is investigating an alert from Microsoft Defender for Identity indicating 'Suspicious service creation' on a domain controller. Upon reviewing the alert details, the analyst determines that a legitimate administrator performed the action as part of a planned maintenance window. To prevent similar false positive alerts in the future for this specific legitimate activity, while still maintaining detection for truly malicious service creations, what action should the analyst take within Microsoft Defender for Identity?
- ADisable the 'Suspicious service creation' detection rule entirely.
- BMark the alert as 'Resolved' without further configuration changes.
- CCreate an exclusion rule for the specific administrative account or activity pattern.
- DSuppress the alert for all 'Suspicious service creation' activities.
Show answer & explanationAnswer & explanation
Correct answer: C. Create an exclusion rule for the specific administrative account or activity pattern.
Creating an exclusion rule allows the security team to specify conditions (e.g., specific user, machine, or activity pattern) under which an alert should not be generated. This prevents false positives for known legitimate activities while keeping the detection rule active for other, potentially malicious, instances.
Why the other options are wrong
- A. Disabling the detection rule entirely would prevent all detection of this threat, including malicious instances, making the environment vulnerable.
- B. Marking as 'Resolved' only addresses the current alert; it doesn't prevent future false positives for the same legitimate activity.
- D. Suppressing all alerts for this type of activity would hide legitimate threats, which is not desired.
Defender for Identity Exclusion Rules
Custom rules configured in Microsoft Defender for Identity to prevent specific legitimate activities from generating security alerts.
- Reduces false positives.
- Allows fine-tuning of detection logic.
- Can be based on users, devices, or activity properties.
Memory trick: Exclude Legitimate Actions to Refine Alerts.