easyMultiple Choice
SC-200 Practice Question: A security operations analyst is reviewing…
A security operations analyst is reviewing recommendations in Microsoft Defender for Cloud. For a virtual machine that is missing critical security updates, which recommendation category will highlight this issue?
⚠ Common exam trap
It's easy for candidates to confuse the 'Regulatory compliance' category with security update tracking, but regulatory compliance only shows compliance with specific standards, not the operational status of missing patches.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secure score
In Microsoft Defender for Cloud, the Secure score category directly reflects the security posture of your resources by tracking the implementation of security recommendations. Missing critical security updates on a virtual machine are flagged as a recommendation within this category, and resolving them improves your secure score percentage. This is because secure score is calculated based on the compliance status of each recommendation, with missing updates being a key control for vulnerability management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Secure score
Why this is correct
Secure score is the correct answer because it aggregates all security recommendations from Microsoft Defender for Cloud, including the specific recommendation 'System updates should be installed on your machines.' Each recommendation contributes to the overall secure score percentage, and the feature directly lists missing critical updates with remediation steps and affected resources, making it the primary location for a security operations analyst to address patch gaps.
- ✗
Regulatory compliance
Why it's wrong here
Regulatory compliance is incorrect because this blade maps your environment's compliance against standards such as CIS, NIST, or PCI DSS, displaying controls and the compliance status of your resources. While missing critical updates might affect compliance results, the feature does not natively generate a prioritized list of missing updates; instead, it reports on regulatory frameworks, so it would not be the first place an analyst would look for patch recommendations.
- ✗
Workload protections
Why it's wrong here
Workload protections is incorrect because this feature focuses on threat detection and response, providing security alerts for active attacks, anomalies, and suspicious behaviors on workloads like VMs, SQL servers, and storage accounts. It does not emit recommendations for missing system updates; rather, it surfaces incidents that require investigation, so it is not the appropriate tool for reviewing missing critical updates.
- ✗
Inventory
Why it's wrong here
Inventory is incorrect because this blade offers a searchable list of all connected resources, displaying metadata such as resource type, resource group, location, and open ports, but it does not analyze or flag missing critical updates. The inventory feature is designed for asset discovery and management, not for vulnerability assessment or providing remediation recommendations, so it would not highlight missing updates for an analyst.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.