An operator dismisses every Medium Microsoft Defender for Cloud alert so the lock-lab blade looks clean. How should the Azure security engineer handle dismissals instead?
Select an answer to reveal the explanation.
Short Explanation
A clean blade isn’t the same as a safe lab. Dismiss only the false positives with a real reason, and keep those High canal alerts cooking until somebody actually fixes them.
Full Explanation
Alert dismissal in Microsoft Defender for Cloud should be reserved for verified false positives and should include justification. High-severity alerts that represent real risk must remain active and tracked until remediation completes. Mass dismissal to tidy the queue, converting alerts into recommendations without analysis, or deleting alerts without review hides threat signal rather than managing it.