Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. A critical incident has been generated from Microsoft Defender for Cloud indicating that a Linux VM in Azure is running a cryptocurrency miner. The VM is part of a production application and cannot be shut down immediately. The incident severity is High. You need to contain the threat while maintaining application availability, investigate the root cause, and prevent recurrence. The environment includes Azure Policy, Microsoft Defender for Endpoint on the VM, and a Log Analytics workspace. You must minimize manual steps. What course of action should you take?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Microsoft Sentinel automation to apply a block rule on the VM's network security group (NSG) to block outbound traffic to known mining pools, initiate Live Response to collect evidence, and create an Azure Policy to automatically deploy Microsoft Defender for Endpoint on all VMs

It uses Microsoft Sentinel automation to apply a network security group (NSG) rule to block outbound traffic to known mining pools, which contains the threat without disrupting the VM's availability for production traffic. Initiating Live Response on the VM allows collection of forensic evidence for investigation. Creating an Azure Policy to enforce Microsoft Defender for Endpoint deployment on all VMs helps prevent recurrence by ensuring all VMs have endpoint detection and response (EDR) capabilities. Option A is incorrect because remotely connecting and killing the process is a manual step that does not block the miner from restarting or communicating outbound, and it may not be immediately effective. Option B is incorrect because removing the VM from the load balancer alone does not stop the miner from running locally or potentially communicating via other routes, and Azure Policy for antivirus is insufficient for modern threats like miners. Option C is incorrect because stopping the VM immediately would disrupt production, and taking a snapshot then redeploying from backup does not address the immediate containment of the threat on the current VM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remotely connect to the VM and run a script to kill the miner process, then update antivirus definitions

    Why it's wrong here

    Remotely connecting and running a script is a manual step, and killing the process does not prevent the miner from restarting or block its network communication; it is not an effective containment strategy for a high-severity incident.

  • ✗

    Remove the VM from the load balancer, then use Azure Policy to enforce that all VMs have antivirus enabled

    Why it's wrong here

    Removing the VM from the load balancer stops traffic from reaching the application but does not contain the miner itself, which can still run locally and potentially communicate outbound through other network paths; Azure Policy for antivirus alone is insufficient.

  • ✗

    Stop the VM immediately, take a snapshot for forensic analysis, and then redeploy a clean VM from a backup

    Why it's wrong here

    Stopping the VM halts the miner but takes the production application offline, violating the availability requirement, and redeploying from backup discards forensic evidence. This approach fits a non-production host where immediate isolation outweighs uptime and root-cause investigation.

  • ✓

    Use Microsoft Sentinel automation to apply a block rule on the VM's network security group (NSG) to block outbound traffic to known mining pools, initiate Live Response to collect evidence, and create an Azure Policy to automatically deploy Microsoft Defender for Endpoint on all VMs

    Why this is correct

    Using Sentinel automation to block outbound traffic to mining pools via NSG rules contains the threat without affecting legitimate traffic; Live Response collects evidence for investigation; Azure Policy to enforce Defender for Endpoint deployment prevents future occurrences by ensuring all VMs have EDR coverage.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.