Using Defender XDR alert tuning rules to hide or resolve alerts and reduce alert fatigue

Respond to alerts and incidents in Microsoft Defender XDR
Answer Correct answer: B, C — Defender XDR alert tuning rules can only hide and resolve alerts to reduce noise; they cannot delete, merge, or assign.

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You discover that when Microsoft Defender for Endpoint generates alerts for a commonly used executable file, it causes alert fatigue. You need to tune the alerts. Which two actions can an alert tuning rule perform for the alerts? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

  1. delete
  2. hide Correct Answer
  3. resolve Correct Answer
  4. merge
  5. assign

Community Votes

BC
100%

100% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Defender XDR alert tuning rules support only two actions — hide and resolve — to reduce noise, so those are the two correct choices; delete, merge, and assign are not tuning actions.

To tune alerts from a commonly used executable that causes alert fatigue in Defender XDR, an alert tuning rule can hide the alerts (remove them from the queue but keep them logged) or resolve them automatically; it cannot delete, merge, or assign.

Picking merge or delete — alert tuning cannot merge alerts or delete them; it can only hide or resolve, so those selections are invalid for a tuning rule.

Community Discussion (3 comments)

landfils 👍 3 Selected: BC
B and C Hide : This action allows you to hide alerts generated by the specified executable file, reducing the noise and alert fatigue. These hidden alerts will not appear in the incident queue but will still be logged for historical purposes. Resolve : This action automatically resolves alerts generated by the specified executable file. The alerts are marked as resolved, indicating that no further action is required. This helps in managing alert fatigue by automatically handling known benign alerts.
RoombaDoinZoomba 👍 1 Selected: BC
Incorrect: https://learn.microsoft.com/en-us/defender-xdr/investigate-alerts?tabs=settings Alert tuning can only hide and resolve alerts to assist, it cannot merge alerts.
tryade 👍 2 Selected: BC
Incorrect, B and C https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/boost-your-detection-and-response-workflows-with-alert-tuning/3824712

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Defender XDR alert tuning rules are designed to reduce alert fatigue and support two actions: hide (keep the alert out of the incident queue while still logging it) and resolve (automatically mark the alert as resolved). These are the only two actions a tuning rule can perform.

Why the Other Options Are Wrong

Delete (A), merge (D), and assign (E) are not actions available to alert tuning rules. Merge, for example, is handled by incident correlation, not by an alert tuning rule.

Community Comment Notes

The community is unanimous (BC 100 votes). landfils describes both hide and resolve precisely, and RoombaDoinZoomba cites the Defender XDR alert settings documentation confirming tuning can only hide and resolve alerts.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide