SC-200 Manage a security operations environment Practice Question
Your company uses Microsoft Defender for Cloud to assess the security posture of hybrid workloads. You are configuring a governance rule to automatically remediate a specific recommendation that is out of compliance. The recommendation is 'Virtual machines should be migrated to new Azure Resource Manager resources'. You need to ensure that the remediation is applied at scale across all subscriptions in the management group. What should you do?
⚠ Common exam trap
A common mix-up: candidates confuse Azure Policy remediation tasks with Defender for Cloud governance rules, not realizing that governance rules provide a simpler, built-in mechanism for automatic remediation of specific recommendations at scale without requiring separate policy assignments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a governance rule in Microsoft Defender for Cloud with scope set to the management group, condition on the recommendation, and action set to 'Automatic'.
Governance rules in Microsoft Defender for Cloud allow you to define automatic remediation actions for specific recommendations at scale. By setting the scope to the management group, the rule applies to all subscriptions within that group, and the 'Automatic' action triggers the built-in remediation script for the 'Virtual machines should be migrated to new Azure Resource Manager resources' recommendation without requiring custom scripting or policy assignments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a PowerShell script that runs on each VM to migrate it, and execute it via Azure Automation.
Why it's wrong here
A custom PowerShell script executed through Azure Automation is not a governance rule; Defender for Cloud governance rules provide built-in automatic remediation scripts for supported recommendations. While Azure Automation runbooks can technically perform remediation, they are not integrated with the governance rule engine, meaning the recommendation's status would not be updated automatically to reflect the remediation, and you'd be bypassing the intended native mechanism.
- ✗
Create an Azure Policy initiative that includes the recommendation and assign it with a remediation task at the management group level.
Why it's wrong here
An Azure Policy initiative with a remediation task addresses policy noncompliance through Azure Policy, but it operates independently of Microsoft Defender for Cloud's governance rule feature. Governance rules specifically assess and act on Defender recommendations, not policy definitions; even if you assign the initiative at the management group, remediation tasks won't automatically flow through into Defender for Cloud's continuous compliance score or governance tracking. The correct approach is not to create a policy initiative but to create a governance rule that targets the recommendation directly.
- ✓
Create a governance rule in Microsoft Defender for Cloud with scope set to the management group, condition on the recommendation, and action set to 'Automatic'.
Why this is correct
To meet the requirement, create a governance rule in Microsoft Defender for Cloud with scope set to the management group, a condition that includes the specific recommendation, and an action of 'Automatic'. Scoping at the management group makes the rule inherit to all subscriptions beneath it, so every VM is assessed, and the 'Automatic' action invokes Defender's built-in remediation capability to migrate the VMs without manual intervention. This is the native mechanism designed for exactly this scenario.
- ✗
Create a governance rule in Microsoft Defender for Cloud with scope set to a single subscription and action set to 'Automatic'.
Why it's wrong here
Setting the governance rule's scope to a single subscription while you have multiple subscriptions under the management group means only that one subscription will be assessed and automatically remediated. Since the requirement is to assess all subscriptions, the rule must be scoped to the management group so that it inherits across every subscription. A single-subscription scope could miss other subscriptions, leaving VMs unassessed and non-compliant.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.