SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. During an incident, you need to automatically disable a compromised Azure VM from the network. Which playbook action should you use?
⚠ Common exam trap
Many exam-takers confuse network-level isolation (NSG rules) with management-plane controls (RBAC) or perimeter-level filtering (Azure Firewall), leading them to choose options that do not actually block all traffic to the compromised VM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a rule to the VM's network security group to deny all traffic.
Adding a rule to the VM's network security group (NSG) to deny all traffic is the most direct and immediate way to isolate a compromised Azure VM at the network level. NSG rules are evaluated in order of priority, and a deny-all rule (e.g., denying any inbound and outbound traffic) effectively cuts off all network communication to and from the VM, which is a common containment step during incident response. This action can be automated via a Microsoft Sentinel playbook using the Azure Network Security Group connector.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply an Azure Policy to deny network changes.
Why it's wrong here
Azure Policy is a governance and compliance service that evaluates resource configurations, but it does not act on existing VM network traffic. Even a 'deny' effect only blocks future configuration changes made by users, not current connectivity. Since the goal is immediate isolation of the compromised VM, policy cannot replace a network-level control.
- ✗
Create an Azure Firewall rule to block the VM's IP.
Why it's wrong here
Azure Firewall is a centralized service that filters traffic only when that traffic is routed through it via user-defined routes or hub/spoke architecture; traffic within the VM's own subnet may never reach it. Therefore, adding a rule to block the VM's IP has no effect unless the VM's traffic path already goes through the firewall, and it may also block other resources sharing the same IP. It is not a reliable method for immediate, VM-specific isolation.
- ✓
Add a rule to the VM's network security group to deny all traffic.
Why this is correct
Adding a deny-all rule to the VM's network security group (NSG) at the network interface level immediately blocks all inbound and outbound traffic to and from that interface, effectively isolating the VM from the rest of the network. NSG rules are evaluated in priority order, so a high-priority deny rule (e.g., priority 100) supersedes any permissive rules. This is the standard and most direct control for isolating a compromised Azure VM.
- ✗
Remove the VM's role assignment from Azure RBAC.
Why it's wrong here
Azure RBAC governs the management plane, controlling who can read, write, or delete Azure resources via the Azure Resource Manager API. Removing the VM's role assignment revokes management privileges but does not alter network packets, IP flows, or the guest OS network stack. The VM remains fully reachable on its existing network paths, so this action cannot stop malicious traffic.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.