exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 2 question 19 discussion

Actual exam question from Microsoft's SC-200
Question #: 19
Topic #: 2
[All SC-200 Questions]

You use Azure Security Center.
You receive a security alert in Security Center.
You need to view recommendations to resolve the alert in Security Center.
What should you do?

  • A. From Security alerts, select the alert, select Take Action, and then expand the Prevent future attacks section.
  • B. From Security alerts, select Take Action, and then expand the Mitigate the threat section.
  • C. From Regulatory compliance, download the report.
  • D. From Recommendations, download the CSV report.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
NickHSO
Highly Voted 3 years, 4 months ago
it is B. With the 'Mitigate the threat' action you receive recommendations to mitigate this threat. The 'Prevent future attacks' action provides security recommendations to help reduce the attack surface, increase security posture, and thus prevent future attacks.
upvoted 22 times
...
Eltooth
Highly Voted 3 years, 7 months ago
Correct answer - B
upvoted 8 times
...
Nikki0222
Most Recent 6 months, 1 week ago
B correct
upvoted 1 times
...
talosDevbot
7 months, 1 week ago
Selected Answer: B
The question is asking for how to resolve the alert. In other words, to respond to an offending security event. Mitigate the threat section involves alerts affecting the device. Prevent future attack deals with reducing attack surface and vulnerability remediation recommendations. Remediating a vulnerability or hardening a devices does not resolve an alert. https://learn.microsoft.com/en-us/azure/defender-for-cloud/managing-and-responding-alerts#respond-to-security-alerts
upvoted 1 times
...
Studytime2023
8 months, 3 weeks ago
Both A and B work (sort of). but the answer is definitely B. When you follow the precise steps of A. You expand "Prevent future attacks" and see: "Solving security recommendations can prevent future attacks by reducing attack surface." In other words, please refer to "Mitigate". If you follow the steps of B. You expand "Mitigate the threat" and see: The specific steps to correct the specific issue. It will also provide a URL to documentation (if applicable) and it will mention if there are any other alerts on the affected resource. *Tested on my MSP's tenant. You can even generate sample alerts to do this if you don't have any*.
upvoted 1 times
xRiot007
4 months, 4 weeks ago
You need to solve the (current) alert. This means that first, you do step B. Then, if you want to protect your system from future threats, you do step A, which is not required in this specific question.
upvoted 1 times
...
...
Avaris
10 months, 2 weeks ago
Selected Answer: A
Option A aligns with Azure Security Center's recommended approach to handling security alerts. By selecting the alert, taking action, and expanding the "Prevent future attacks" section, you will access detailed guidance on how to mitigate the identified threat and strengthen your security posture to prevent similar incidents. This is consistent with how Azure Security Center organizes its guidance and recommendations.
upvoted 1 times
...
ggGG1357
1 year, 4 months ago
Selected Answer: B
B is correct. Because it is dealing with a current issue. The question is dealing with a present security alert. So be will be suitable. A would be an option for future attacks.
upvoted 2 times
...
ggGG1357
1 year, 4 months ago
B is correct. Because it is dealing with a current issue. The question is dealing with a present security alert. So be will be suitable. A would be an option for future attacks.
upvoted 1 times
...
chepeerick
1 year, 6 months ago
Correct A
upvoted 2 times
...
Gurulee
1 year, 6 months ago
Selected Answer: A
They question is asking for “view recommendations”, therefore the best answer is A. “Prevent future attacks - provides security recommendations to help reduce the attack surface, increase security posture, and thus prevent future attacks”
upvoted 1 times
Gurulee
1 year, 6 months ago
Now I’m leaning toward B 😳
upvoted 1 times
Gurulee
1 year, 4 months ago
Mitigate the threat provides steps to remediate said threat. Whereas Prevent future attacks offers security recommendations to minimize attack surface on the host.
upvoted 1 times
liveup2it
11 months, 1 week ago
Before you can click Take Action, you first have to select the alert. Answer B skips this part, so cannot be correct. Leaves us with Answer A.
upvoted 1 times
...
...
...
...
sand5234
1 year, 7 months ago
Correct Answer - A Tested
upvoted 1 times
...
Anil0512
1 year, 7 months ago
it'a A
upvoted 2 times
Ramye
1 year, 2 months ago
No. It's B because it asked to resolve the alert that you have already received. A is for the future.
upvoted 1 times
...
...
mali1969
1 year, 8 months ago
Selected Answer: A
Correct answer is A. From Security alerts, select the alert, select Take Action, and then expand the Prevent future attacks section. This will show you the security recommendations to help reduce the attack surface, increase security posture, and thus prevent future attacks. To view the recommendations, you can follow these steps: From Defender for Cloud’s security alerts page, select the alert you want to resolve. Select Take Action at the top of the alert details page. Expand the Prevent future attacks section and review the recommendations.
upvoted 2 times
...
XLR8T2
1 year, 9 months ago
Hola a todos, para esta pregunta la respuesta correcta es la A, acabo de validarlo, tienes que seleccionar la alerta para que luego puedas seleccionar Take Action. Microsoft Defender for Cloud -> Security Alerts -> Select Alert -> Select Take Action ...
upvoted 1 times
...
tatendazw
1 year, 10 months ago
A is the answer, only Prevent future attacks - provides security recommendations to help reduce the attack surface, increase security posture, and thus prevent future attacks B is incorrect because Mitigate the threat - provides manual remediation steps for this security alert https://learn.microsoft.com/en-us/azure/defender-for-cloud/managing-and-responding-alerts#respond-to-security-alerts
upvoted 1 times
xRiot007
4 months, 4 weeks ago
B is correct because that's exactly what you have to do first: solve the alert issue. it is irrelevant if you do it manually.
upvoted 1 times
...
...
Lone__Wolf
2 years, 2 months ago
Selected Answer: B
The correct answer is B. From Security alerts, select Take Action, and then expand the Mitigate the threat section. To view recommendations to resolve a security alert in Azure Security Center, you should follow these steps: Go to the Security alerts page in Security Center. Select the specific security alert that you want to view recommendations for. Select the Take Action button. Expand the Mitigate the threat section to view the recommended steps for resolving the alert. These recommendations provide detailed information and steps for addressing the security issue that is raised by the alert, and help you to prevent future attacks on your resources. By following the recommendations, you can improve the security posture of your resources in Azure.
upvoted 4 times
...
amsioso
2 years, 7 months ago
B Mitigate the threat - provides manual remediation steps (recommendations to resolve) for this security alert But they forgot "select the alert"
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago