nerdexam
Microsoft

SC-200 · Question #179

You have an Azure subscription that uses Microsoft Defender for Cloud. You need to filter the security alerts view to show the following alerts: - Unusual user accessed a key vault - Log on from an…

The correct answer is C. Medium. The three alerts listed - 'Unusual user accessed a key vault,' 'Log on from an unusual location,' and 'Impossible travel activity' - are all classified as Medium severity in Microsoft Defender for Cloud. They represent suspicious behaviors that may indicate a compromise but are…

Submitted by marco_it· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Cloud

Question

You have an Azure subscription that uses Microsoft Defender for Cloud. You need to filter the security alerts view to show the following alerts:

  • Unusual user accessed a key vault
  • Log on from an unusual location
  • Impossible travel activity

Which severity should you use?

Options

  • AInformational
  • BLow
  • CMedium
  • DHigh

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    14% (5)
  • C
    78% (28)
  • D
    3% (1)

Explanation

The three alerts listed - 'Unusual user accessed a key vault,' 'Log on from an unusual location,' and 'Impossible travel activity' - are all classified as Medium severity in Microsoft Defender for Cloud. They represent suspicious behaviors that may indicate a compromise but are not confirmed active attacks. High severity is reserved for imminent or confirmed threats, while Low and Informational are for minor anomalies or policy notifications. Filtering by Medium will surface all three of these alerts.

Topics

#Security Alerts#Microsoft Defender for Cloud#Alert Severity

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice