Courseiva
easyMultiple Choice

SC-200 Practice Question: A security analyst receives an alert in Microsoft…

A security analyst receives an alert in Microsoft Defender for Cloud that an Azure virtual machine is running a process with a known indicator of compromise (IOC). The analyst wants to investigate the process details, including the command line and parent process. Which feature should the analyst use to gather this information from the VM?

⚠ Common exam trap

Test-takers frequently confuse Live Response with Vulnerability Assessment or Inventory, thinking those can provide process-level details, but only Live Response offers interactive, real-time forensic access to the VM's operating system.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Live response

Live Response in Microsoft Defender for Cloud provides a remote shell connection to the VM, allowing the analyst to run commands to inspect running processes, command-line arguments, and parent process details in real time. This is the correct feature for deep forensic investigation of an active IOC on the VM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vulnerability assessment

    Why it's wrong here

    Vulnerability assessment in Defender for Cloud (typically backed by Qualys or Microsoft Defender for Endpoint) is a periodic, agent-based scan that surfaces known CVEs, missing patches, and security misconfigurations on a machine. It does not provide a live shell or the ability to enumerate running processes with their command-line arguments, so it is not suitable for investigating the specific process that triggered an alert.

  • ✓

    Live response

    Why this is correct

    Live response is correct because it gives an analyst a remote interactive shell into a Windows or Linux VM, enabling built-in investigation commands such as process listing, network connection enumeration, and scheduled task review in real time. This directly matches the alert-handling need to inspect what a particular process executed on the host, and it also supports collecting forensic artifacts for further analysis.

  • ✗

    Inventory of resources

    Why it's wrong here

    The inventory of resources feature in Defender for Cloud presents a queryable list of Azure resources with metadata such as resource groups, locations, and security configurations, but it reflects only control-plane information. It cannot reach into the guest operating system, so it has no ability to show process details, command lines, or other runtime evidence for a compromised workload.

  • ✗

    Secure score

    Why it's wrong here

    Secure score is a risk-based metric that aggregates the effect of recommended security controls and indicates how well a tenant follows industry best practices. It is a high-level posture measurement, not an investigation tool, and it cannot provide per-machine process data or help an analyst examine the specific command line that triggered the alert.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.