SC-200 Respond to security incidents • Set 32
SC-200 Respond to security incidents Practice Test 32 — 15 questions with explanations. Free, no signup.
Your organization uses Microsoft Sentinel and Microsoft Defender XDR. A critical incident has been generated from Microsoft Defender for Cloud indicating that a Linux VM in Azure is running a cryptocurrency miner. The VM is part of a production application and cannot be shut down immediately. The incident severity is High. You need to contain the threat while maintaining application availability, investigate the root cause, and prevent recurrence. The environment includes Azure Policy, Microsoft Defender for Endpoint on the VM, and a Log Analytics workspace. You must minimize manual steps. What course of action should you take?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.