SC-200 Respond to security incidents • Set 30
SC-200 Respond to security incidents Practice Test 30 — 15 questions with explanations. Free, no signup.
After a security incident, the SOC team needs to preserve forensic evidence from a compromised Microsoft Entra ID joined Windows 10 device. The device is still online. Which tool should the team use to collect a forensic image of the hard drive?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.