SC-200 Respond to security incidents • Set 25
SC-200 Respond to security incidents Practice Test 25 — 15 questions with explanations. Free, no signup.
An incident in Microsoft Defender XDR shows a device with high severity alert: 'Suspicious PowerShell command line.' The device is currently isolated from the network. What is the best next step to investigate the alert?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.