Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You receive an alert from Defender for Cloud that a virtual machine has a high severity vulnerability: 'CVE-2023-XXXX' with a CVSS score of 9.8. The virtual machine is running a critical application for the finance department. You need to remediate the vulnerability as quickly as possible while minimizing downtime. The application vendor has not yet released a patch but has provided a workaround. What should you do?

⚠ Common exam trap

SC-200 often tests whether candidates choose the most extreme action (shutdown, full network block) instead of the proportionate, tracked mitigation that keeps the business running.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement the workaround provided by the vendor and create a custom remediation task in Defender for Cloud to track the issue.

When no vendor patch exists but a workaround is available, applying the workaround immediately mitigates the risk while a custom remediation task in Defender for Cloud tracks the issue until a permanent patch arrives. This balances urgency (CVSS 9.8 is critical) with the business need to keep the finance application running.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Dismiss the alert as a false positive because no patch is available.

    Why it's wrong here

    Dismissing the alert discards a CVSS 9.8 finding on a finance-critical VM; the vendor workaround exists precisely to mitigate unpatched vulnerabilities, so the alert should be actioned, not closed. Dismissal suits confirmed benign detections, such as a scanner artefact matching no real asset.

  • ✗

    Shut down the virtual machine until a patch is available.

    Why it's wrong here

    Shutting down the VM guarantees full outage of the finance application, violating the minimise-downtime requirement, whereas the vendor workaround remediates without stopping the service. Powering off is defensible only when no mitigation exists and the host must be isolated immediately.

  • ✓

    Implement the workaround provided by the vendor and create a custom remediation task in Defender for Cloud to track the issue.

    Why this is correct

    Applying the vendor workaround mitigates the CVSS 9.8 exposure immediately without downtime, since no patch exists, and the custom remediation task tracks the risk until a permanent fix arrives. This satisfies the stem's requirement to remediate quickly while minimising downtime.

  • ✗

    Apply a network security group to block all inbound traffic to the VM.

    Why it's wrong here

    Blocking all inbound traffic halts legitimate finance application access, causing the downtime the scenario forbids, and leaves the vulnerability itself unaddressed. An NSG suits restricting exposure to specific hostile sources, not remediating a CVE that the vendor workaround already mitigates.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.