SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel and Microsoft Defender XDR. A critical incident has been generated from Microsoft Defender for Cloud indicating that a Linux VM in Azure is running a cryptocurrency miner. The VM is part of a production application and cannot be shut down immediately. The incident severity is High. You need to contain the threat while maintaining application availability, investigate the root cause, and prevent recurrence. The environment includes Azure Policy, Microsoft Defender for Endpoint on the VM, and a Log Analytics workspace. You must minimize manual steps. What course of action should you take?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Microsoft Sentinel automation to apply a block rule on the VM's network security group (NSG) to block outbound traffic to known mining pools, initiate Live Response to collect evidence, and create an Azure Policy to automatically deploy Microsoft Defender for Endpoint on all VMs
It uses Microsoft Sentinel automation to apply a network security group (NSG) rule to block outbound traffic to known mining pools, which contains the threat without disrupting the VM's availability for production traffic. Initiating Live Response on the VM allows collection of forensic evidence for investigation. Creating an Azure Policy to enforce Microsoft Defender for Endpoint deployment on all VMs helps prevent recurrence by ensuring all VMs have endpoint detection and response (EDR) capabilities. Option A is incorrect because remotely connecting and killing the process is a manual step that does not block the miner from restarting or communicating outbound, and it may not be immediately effective. Option B is incorrect because removing the VM from the load balancer alone does not stop the miner from running locally or potentially communicating via other routes, and Azure Policy for antivirus is insufficient for modern threats like miners. Option C is incorrect because stopping the VM immediately would disrupt production, and taking a snapshot then redeploying from backup does not address the immediate containment of the threat on the current VM.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remotely connect to the VM and run a script to kill the miner process, then update antivirus definitions
Why it's wrong here
Remotely connecting and running a script is a manual step, and killing the process does not prevent the miner from restarting or block its network communication; it is not an effective containment strategy for a high-severity incident.
- ✗
Remove the VM from the load balancer, then use Azure Policy to enforce that all VMs have antivirus enabled
Why it's wrong here
Removing the VM from the load balancer stops traffic from reaching the application but does not contain the miner itself, which can still run locally and potentially communicate outbound through other network paths; Azure Policy for antivirus alone is insufficient.
- ✗
Stop the VM immediately, take a snapshot for forensic analysis, and then redeploy a clean VM from a backup
Why it's wrong here
Stopping the VM halts the miner but takes the production application offline, violating the availability requirement, and redeploying from backup discards forensic evidence. This approach fits a non-production host where immediate isolation outweighs uptime and root-cause investigation.
- ✓
Use Microsoft Sentinel automation to apply a block rule on the VM's network security group (NSG) to block outbound traffic to known mining pools, initiate Live Response to collect evidence, and create an Azure Policy to automatically deploy Microsoft Defender for Endpoint on all VMs
Why this is correct
Using Sentinel automation to block outbound traffic to mining pools via NSG rules contains the threat without affecting legitimate traffic; Live Response collects evidence for investigation; Azure Policy to enforce Defender for Endpoint deployment prevents future occurrences by ensuring all VMs have EDR coverage.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.