easyMultiple Choice
SC-200 Practice Question: A security analyst receives an alert in Microsoft…
A security analyst receives an alert in Microsoft Defender for Cloud that an Azure virtual machine is running a process with a known indicator of compromise (IOC). The analyst wants to investigate the process details, including the command line and parent process. Which feature should the analyst use to gather this information from the VM?
⚠ Common exam trap
Test-takers frequently confuse Live Response with Vulnerability Assessment or Inventory, thinking those can provide process-level details, but only Live Response offers interactive, real-time forensic access to the VM's operating system.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Live response
Live Response in Microsoft Defender for Cloud provides a remote shell connection to the VM, allowing the analyst to run commands to inspect running processes, command-line arguments, and parent process details in real time. This is the correct feature for deep forensic investigation of an active IOC on the VM.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vulnerability assessment
Why it's wrong here
Vulnerability assessment in Defender for Cloud (typically backed by Qualys or Microsoft Defender for Endpoint) is a periodic, agent-based scan that surfaces known CVEs, missing patches, and security misconfigurations on a machine. It does not provide a live shell or the ability to enumerate running processes with their command-line arguments, so it is not suitable for investigating the specific process that triggered an alert.
- ✓
Live response
Why this is correct
Live response is correct because it gives an analyst a remote interactive shell into a Windows or Linux VM, enabling built-in investigation commands such as process listing, network connection enumeration, and scheduled task review in real time. This directly matches the alert-handling need to inspect what a particular process executed on the host, and it also supports collecting forensic artifacts for further analysis.
- ✗
Inventory of resources
Why it's wrong here
The inventory of resources feature in Defender for Cloud presents a queryable list of Azure resources with metadata such as resource groups, locations, and security configurations, but it reflects only control-plane information. It cannot reach into the guest operating system, so it has no ability to show process details, command lines, or other runtime evidence for a compromised workload.
- ✗
Secure score
Why it's wrong here
Secure score is a risk-based metric that aggregates the effect of recommended security controls and indicates how well a tenant follows industry best practices. It is a high-level posture measurement, not an investigation tool, and it cannot provide per-machine process data or help an analyst examine the specific command line that triggered the alert.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.