Microsoft Defender for Cloud raises a High storage-malware alert on the lock-photo storage account. What should the Azure security engineer do first as part of managing the alert?
Select an answer to reveal the explanation.
Short Explanation
Don’t yank the storage account on the first beep. Triage the High alert—confirm or dismiss with a reason, park an owner on it, and track status—then remediate with eyes open.
Full Explanation
Managing Microsoft Defender for Cloud alerts at security-engineer depth means triaging: confirm the finding, dismiss only with justification when appropriate, assign an owner, and track status through remediation. Deleting the storage account as the first click skips investigation and ownership. Security Copilot is out of scope for this AZ-500 alert-management skill, and downgrading severity to clean a queue is not a valid response pattern.