Courseiva
mediumMultiple Choice

SC-200 Practice Question: A cloud security administrator receives an alert…

A cloud security administrator receives an alert from Microsoft Defender for Cloud indicating that a virtual machine has been compromised. The administrator wants to quickly isolate the VM from the network to prevent further spread while preserving the disk for forensic analysis. Which action should the administrator take?

⚠ Common exam trap

Test-takers frequently confuse Just-In-Time (JIT) access with network isolation, mistakenly thinking restricting management ports is sufficient to contain a compromise, when in fact JIT does not block lateral movement or outbound malicious traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the "Isolate VM" action in the security alert.

The 'Isolate VM' action in Microsoft Defender for Cloud is designed specifically for compromised VMs. It applies a network security group (NSG) rule that denies all inbound and outbound traffic to the VM, effectively quarantining it from the network while leaving the disk intact for forensic analysis. This is the fastest and most direct method to contain the threat without altering the VM's configuration or disk state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply a just-in-time (JIT) access policy to the VM.

    Why it's wrong here

    Apply a just-in-time (JIT) access policy to the VM limits inbound management traffic to whitelisted IP addresses for a finite window, but it does nothing to interrupt an already compromised VM's communication with the network. A threat actor with existing access can continue lateral movement to other resources, and the VM's disk, processes, and open connections remain fully operational. JIT is a preventive control for reducing attack surface, not a containment mechanism for an active incident.

  • ✓

    Use the "Isolate VM" action in the security alert.

    Why this is correct

    Use the 'Isolate VM' action in the security alert is the correct immediate response because Defender for Cloud dynamically attaches a network security group to the VM's network interface that blocks all inbound and outbound traffic, while still allowing only the Defender service's management and forensic paths. This quarantines the compromised VM without deleting or detaching its disk, preserving evidence for investigation. The action is designed for exactly this kind of incident-response need: rapid, built-in network containment without disrupting connectivity to other Azure services that the investigation depends on.

  • ✗

    Enable the Azure Security Benchmark initiative for the VM.

    Why it's wrong here

    Enable the Azure Security Benchmark initiative for the VM applies a set of Azure Policy definitions that evaluate configuration, compliance, and hardening baselines, such as encryption, logging, or secure ports. This is a long-term governance action that only reports on or auto-remediates non-compliant resource settings; it does not change the network-level state of an already compromised VM. Because the benchmark initiative is not an incident-response tool, it cannot stop active malicious traffic or isolate the VM from the network.

  • ✗

    Configure a custom Azure Policy to deny network access.

    Why it's wrong here

    Configure a custom Azure Policy to deny network access is conceptually wrong because Azure Policy enforces resource-level configuration and compliance at evaluation time—typically during resource creation or when there is a configuration drift—and it does not act on live network traffic or perform runtime isolation. Even if you define a policy that denies network access, it would not immediately block connections to an existing VM's network interface; you would need a Network Security Group or a network intent policy. Azure Policy is an effective control for defining and auditing guardrails, not for real-time containment of a security alert.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.