Courseiva

SC-200 Respond to security incidents Practice Question

Your organization is using Microsoft Defender for Cloud to protect Azure workloads. A critical vulnerability was discovered in a virtual machine that is part of a production application. The vulnerability has a high severity score and is actively being exploited in the wild. You need to respond quickly to mitigate the risk. What is the most effective immediate action?

⚠ Common exam trap

Many candidates choose the 'Remediate' option (D) thinking it automatically patches the vulnerability, but in reality, the patch may not be available or may require a reboot, making JIT access the faster and safer immediate containment action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable just-in-time (JIT) VM access in Microsoft Defender for Cloud to lock down inbound traffic.

Enabling just-in-time (JIT) VM access in Microsoft Defender for Cloud immediately reduces the attack surface by locking down inbound traffic to the VM, except for approved connections from specific IP addresses and ports. This is the most effective immediate action when a critical, actively exploited vulnerability exists, as it buys time to apply a patch without exposing the VM to further exploitation. Unlike patching, which may require a reboot or cause downtime, JIT access can be enabled in minutes and does not disrupt production traffic for authorized users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply the vendor patch immediately during business hours.

    Why it's wrong here

    Applying a vendor patch immediately during business hours is not an effective immediate response because most change windows require testing, approval, and planned downtime, and the patch itself may not yet be available or may introduce regressions. During active exploitation, you need rapid containment, not a multi-hour disruption to production traffic. Patch deployment should occur after reducing the attack surface, and business-hours patching amplifies availability impact without guaranteeing faster mitigation.

  • ✓

    Enable just-in-time (JIT) VM access in Microsoft Defender for Cloud to lock down inbound traffic.

    Why this is correct

    Enabling just-in-time (JIT) VM access in Microsoft Defender for Cloud immediately reduces the attack surface by creating temporary NSG rules that only allow specified source IPs and ports during defined schedules. This blocks inbound traffic from the internet or other high-risk sources while preserving legitimate administrative access, unlike a full inbound block. JIT is a fast, reversible, and targeted network-level control that buys time for a safe patch deployment without taking the VM offline.

  • ✗

    Modify the network security group (NSG) to block all inbound traffic to the VM.

    Why it's wrong here

    Modifying the network security group (NSG) to block all inbound traffic is an overly broad control that will likely break legitimate application traffic and user connectivity, causing a denial of service. It also may not protect against lateral movement from within the virtual network or from compromised peered networks unless applied to all interfaces and subnets, and is not a surgical response. JIT is preferred because it allows required traffic to continue while still mitigating the exploited vulnerability.

  • ✗

    Use the 'Remediate' option in Defender for Cloud to automatically apply the patch.

    Why it's wrong here

    The 'Remediate' option in Defender for Cloud is not a one-click automatic patching feature for OS vulnerabilities; it can only apply built-in remediation scripts for certain recommendations, not vendor security updates. Even if it initiated a patch download, it would require a reboot and is not designed as an immediate response to active exploitation. This option also duplicates the slower patching path when you actually need immediate network containment through JIT.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.