Courseiva
easyMultiple Choice

SC-200 Practice Question: A security operations analyst is reviewing…

A security operations analyst is reviewing recommendations in Microsoft Defender for Cloud. For a virtual machine that is missing critical security updates, which recommendation category will highlight this issue?

⚠ Common exam trap

It's easy for candidates to confuse the 'Regulatory compliance' category with security update tracking, but regulatory compliance only shows compliance with specific standards, not the operational status of missing patches.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Secure score

In Microsoft Defender for Cloud, the Secure score category directly reflects the security posture of your resources by tracking the implementation of security recommendations. Missing critical security updates on a virtual machine are flagged as a recommendation within this category, and resolving them improves your secure score percentage. This is because secure score is calculated based on the compliance status of each recommendation, with missing updates being a key control for vulnerability management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Secure score

    Why this is correct

    Secure score is the correct answer because it aggregates all security recommendations from Microsoft Defender for Cloud, including the specific recommendation 'System updates should be installed on your machines.' Each recommendation contributes to the overall secure score percentage, and the feature directly lists missing critical updates with remediation steps and affected resources, making it the primary location for a security operations analyst to address patch gaps.

  • ✗

    Regulatory compliance

    Why it's wrong here

    Regulatory compliance is incorrect because this blade maps your environment's compliance against standards such as CIS, NIST, or PCI DSS, displaying controls and the compliance status of your resources. While missing critical updates might affect compliance results, the feature does not natively generate a prioritized list of missing updates; instead, it reports on regulatory frameworks, so it would not be the first place an analyst would look for patch recommendations.

  • ✗

    Workload protections

    Why it's wrong here

    Workload protections is incorrect because this feature focuses on threat detection and response, providing security alerts for active attacks, anomalies, and suspicious behaviors on workloads like VMs, SQL servers, and storage accounts. It does not emit recommendations for missing system updates; rather, it surfaces incidents that require investigation, so it is not the appropriate tool for reviewing missing critical updates.

  • ✗

    Inventory

    Why it's wrong here

    Inventory is incorrect because this blade offers a searchable list of all connected resources, displaying metadata such as resource type, resource group, location, and open ports, but it does not analyze or flag missing critical updates. The inventory feature is designed for asset discovery and management, not for vulnerability assessment or providing remediation recommendations, so it would not highlight missing updates for an analyst.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.