SC-200 • Practice Exam 70
Free SC-200 practice exam — 20 questions with explanations. Set 70. No signup required.
After a security incident, the SOC team needs to preserve forensic evidence from a compromised Microsoft Entra ID joined Windows 10 device. The device is still online. Which tool should the team use to collect a forensic image of the hard drive?