Lock-lab virtual machines are deallocated overnight and agentless findings look stale. What limitation should the Azure security engineer account for?
Select an answer to reveal the explanation.
Short Explanation
Parked (deallocated) lab VMs don’t get a fresh agentless pass—the disks need to be on supported, running machines. Schedule the scan window while the lab is awake.
Full Explanation
Official agentless scanning prerequisites exclude deallocated machines; fresh results require running virtual machines with supported disks. Scheduling scan windows while machines are allocated addresses stale findings. Assuming deallocated VMs scan best, or that Security Copilot refreshes stopped-disk agentless results, contradicts the product limitations.