Microsoft Security Operations Analyst Associate SC-200 Practice Question

You open a high-severity alert generated by Microsoft Defender for Cloud for an Azure virtual machine that is covered by Defender for Servers Plan 2. You must determine which process on the VM initiated the suspicious outbound connection and then block it from executing. Which built-in action on the alert page should you select first?

  • Download the alert details as a CSV file

  • Investigate in Microsoft Defender for Endpoint

  • Open the affected resources in Azure Resource Graph Explorer

  • Trigger the linked Azure Logic Apps remediation playbook

Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot