SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Defender for Cloud. You need to remediate a security recommendation that indicates a virtual machine is missing critical security updates. Which TWO actions should you take to remediate this recommendation?
⚠ Common exam trap
Many exam-takers confuse 'remediate' with 'suppress' or 'mitigate'—they may choose to create an exemption (Option C) or block traffic (Option A) thinking it resolves the recommendation, but only installing updates or enabling automatic updates actually addresses the root cause.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Connect to the VM and install the missing updates.
Installing the missing updates directly on the VM resolves the underlying vulnerability that Defender for Cloud identified. Option D is correct because configuring automatic updates ensures the VM receives future critical security patches without manual intervention, which proactively remediates the recommendation over time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a network security group to block inbound traffic to the VM.
Why it's wrong here
Adding a network security group to block inbound traffic is not a valid remediation for missing updates because NSGs filter network traffic at the subnet or NIC level, but they do not install operating system patches or alter the software configuration on the VM. The vulnerability remains present and could be exploited by an attacker with local access or through network paths not covered by the NSG, so this action does not resolve the recommendation.
- ✓
Connect to the VM and install the missing updates.
Why this is correct
Connecting to the VM and installing the missing updates directly resolves the configuration issue identified by Microsoft Defender for Cloud. This action applies the required patches, bringing the system into compliance with the security baseline and eliminating the known vulnerabilities. It is the immediate and definitive remediation for a recommendation that reports missing updates.
- ✗
Create an exemption for the recommendation in Defender for Cloud.
Why it's wrong here
Creating an exemption for the recommendation in Defender for Cloud does not remediate the VM; it merely suppresses the finding from your compliance and security dashboards. Exemptions are intended for situations where a risk is accepted by management or the resource is regulated in a way that makes the recommendation non-applicable. The underlying missing updates remain and leave the VM vulnerable to exploitation, so this is not a technical fix.
- ✓
Configure the VM to automatically install updates from Windows Update.
Why this is correct
Configuring the VM to automatically install updates from Windows Update is a correct preventive action because it ensures the operating system receives security patches as they are released. This approach addresses the root cause of the recommendation by establishing a continuous patch-management cycle, and over time it will remediate the current missing updates once the Windows Update service next runs. It is particularly suitable for maintaining long-term compliance rather than applying a single manual fix.
- ✗
Restart the VM to trigger update installation.
Why it's wrong here
Restarting the VM does not install missing updates; it only reboots the operating system. For a restart to trigger update installation, the updates must already have been downloaded and staged on disk, which is not the case here according to the recommendation. Simply restarting the machine without first applying updates will leave the VM in the same unpatched state, and Defender for Cloud will continue to report the vulnerability.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.