Courseiva

SC-200 Memory dump Practice Question

After a security incident, you need to collect forensic evidence from a Windows 10 machine. Which Microsoft tool should you use to create a memory dump?

⚠ Common exam trap

The trap is that candidates may assume Sysinternals tools (like NotMyFault) are the dedicated memory dump tools, but they create crash dumps by crashing the system, which destroys volatile evidence. In the context of forensic collection within Microsoft Defender XDR, Live Response is the correct method to capture a memory dump nondestructively.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Endpoint Live Response

Microsoft Defender for Endpoint Live Response provides a `dump` command that can capture a full memory dump from a live Windows 10 system without causing a crash. This preserves volatile forensic evidence such as running processes, network connections, and encryption keys. In contrast, the Microsoft Crash Dump Tool (NotMyFault or Sysinternals) is designed to trigger a system crash (BSOD) for debugging purposes, which is destructive and not appropriate for forensic collection. Therefore, for a security incident requiring a memory dump without system disruption, Live Response is the correct tool.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remote Desktop Protocol (RDP)

    Why it's wrong here

    RDP provides interactive desktop access and cannot capture the contents of physical memory; it is the correct tool for remote administration, not forensic acquisition. Memory capture requires a dedicated imaging utility that reads RAM directly from the running system.

  • ✓

    Microsoft Defender for Endpoint Live Response

    Why this is correct

    Live Response connects to the device through Microsoft Defender for Endpoint and can run the 'getfile' or memory-dump collection commands, capturing volatile memory without disrupting the host. This satisfies the forensic-evidence constraint by preserving RAM contents for offline analysis.

  • ✗

    Microsoft Crash Dump Tool (e.g., NotMyFault or Sysinternals tools)

    Why it's wrong here

    NotMyFault and Sysinternals tools trigger or analyse crashes; they do not capture a live memory image of a running Windows 10 host. WinPmem or DumpIt performs that acquisition. Crash-dump utilities suit post-bugcheck analysis of kernel dumps, not incident-response memory collection.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps monitors and governs cloud application usage through APIs and logs; it does not execute on endpoints or acquire volatile memory. It is the correct tool for discovering shadow IT and enforcing cloud app policies, not for host forensic collection.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.