Your company uses Microsoft Defender for Endpoint. A device shows signs of compromise with suspicious PowerShell execution. You need to collect forensic evidence before performing remediation. Which action should you use?
Collecting the investigation package gathers volatile forensic artefacts — running processes, scheduled tasks, network connections and autorun entries — from the compromised device before remediation alters them. This satisfies the stem's requirement to preserve evidence first, whereas isolating or remediating the device would destroy the volatile data needed for later analysis.
Why this answer
In Microsoft Defender for Endpoint, the 'Collect investigation package' action gathers a forensic snapshot of the device — including running processes, network connections, autoruns, scheduled tasks, and recent files — without altering the system state. This is the correct first step when you need to preserve evidence before remediation, because it captures volatile data that would be lost if you isolated or remediated the device. Isolation and live response are separate actions that serve different purposes.
Exam trap
SC-200 often tests the order of incident response actions — candidates pick 'Isolate the device' because it sounds like the most urgent step, but the question specifically asks for evidence collection before remediation, making 'Collect investigation package' the correct choice.
How to eliminate wrong answers
Option A is wrong because isolating the device from the network stops the attack but does not collect forensic evidence — it actually prevents further live data collection from the network and is a containment action, not an evidence-gathering one. Option B is wrong because running a full antivirus scan may quarantine or delete malicious files, destroying evidence, and it does not produce a forensic package. Option D is wrong because a live response session gives you a remote shell to run commands on the device, but it is an interactive tool — it does not automatically collect and package forensic artifacts the way 'Collect investigation package' does.