SC-200 Respond to security incidents • Set 13
SC-200 Respond to security incidents Practice Test 13 — 15 questions with explanations. Free, no signup.
During a ransomware incident, an analyst needs to identify which files were encrypted on an endpoint. The endpoint is running Windows and is managed by Microsoft Defender for Endpoint. Which data source should the analyst query in Advanced hunting?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.