SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Defender for Cloud to assess the security posture of Azure subscriptions. You receive an alert that a critical vulnerability exists on a virtual machine. What is the BEST immediate action to validate the alert and contain the threat?
⚠ Common exam trap
SC-200 often tests the importance of validating alerts before taking action, as candidates may rush to containment or remediation without first reviewing the alert details, leading to unnecessary disruptions or ineffective responses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the alert details in Microsoft Defender for Cloud to identify the vulnerability and follow the remediation steps.
The best immediate action is to review the alert details in Microsoft Defender for Cloud because it provides the specific vulnerability, affected resource, and recommended remediation steps. This validation step ensures you understand the threat before taking containment actions, which is critical for an effective and proportionate response. Defender for Cloud's alerts include contextual information such as severity, MITRE tactics, and remediation guidance, enabling informed decision-making.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Contact Microsoft support to request a vulnerability assessment.
Why it's wrong here
Microsoft support does not perform vulnerability validation for Defender for Cloud alerts; the assessment data already exists in the portal. Escalating to support is tempting when alerts seem unclear, but the correct immediate step is investigating the alert's evidence and containing the VM directly.
- ✗
Immediately apply the latest security patches to the VM using Azure Update Manager.
Why it's wrong here
Patching remediates the vulnerability but does not validate the alert or contain an active threat; it also takes time and may not address exploitation already underway. Azure Update Manager is the right tool for routine patch compliance, yet the immediate priority is confirming and isolating the affected VM.
- ✗
Isolate the VM from the network by applying a network security group rule.
Why it's wrong here
A network security group rule blocks traffic to and from the VM, but the stem asks first to validate the alert; isolation alone skips confirming the vulnerability and may disrupt services unnecessarily. NSG rules are the right control for segmenting workloads once a threat is confirmed.
- ✓
Review the alert details in Microsoft Defender for Cloud to identify the vulnerability and follow the remediation steps.
Why this is correct
Reviewing the alert details in Microsoft Defender for Cloud confirms the specific vulnerability and affected resource, then applying the documented remediation steps contains the threat. This validates before acting, satisfying the requirement for the best immediate action rather than unverified escalation or disabling the virtual machine.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.