A critical CVE sits on IIS on a lock-lab virtual machine and appears as a Microsoft Defender Vulnerability Management recommendation. What should the Azure security engineer do first?
Select an answer to reveal the explanation.
Short Explanation
Critical IIS CVE on the lock box? Patch it, remove it, or mitigate it—and watch the MDVM finding close. A shiny Sentinel rule is not the first bandage for a known hole.
Full Explanation
Implementing Microsoft Defender Vulnerability Management includes remediating vulnerable components—patch, remove, or mitigate—until the finding closes in Defender for Cloud. Writing a Sentinel analytics rule first, mass-dismissing findings, or redesigning enterprise patch infrastructure as the immediate answer misses the remediate-the-vulnerability skill. WSUS or ConfigMgr design is not the AZ-500 focus for this item.