easyMultiple ChoiceObjective-mapped
SC-200 Practice Question: An analyst is investigating a malware incident in…
An analyst is investigating a malware incident in Microsoft 365 Defender and has isolated the compromised device using automated investigation and response. The analyst now needs to collect a copy of a suspicious file from that device for further analysis in a sandbox. Which action should the analyst take from the device's entity page?
⚠ Common exam trap
Test-takers frequently confuse the 'Collect investigation package' action with a live response session, assuming manual file download is required, but the exam tests the understanding that automated collection is the preferred method for gathering forensic data from an isolated device without interactive overhead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Initiate 'Collect investigation package' action.
The 'Collect investigation package' action is the correct choice because it is specifically designed to gather a comprehensive set of forensic data from a device, including suspicious files, without requiring interactive access. This action automatically collects the file and other relevant artifacts, which can then be submitted to Microsoft 365 Defender's sandbox for analysis. It is a one-click, automated process that aligns with the analyst's need to obtain a copy of the file for further investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Initiate 'Collect investigation package' action.
Why this is correct
The 'Collect investigation package' action instructs Microsoft Defender for Endpoint to gather a comprehensive forensic zip from the device, containing running processes, services, event logs, registry keys, and key system files—including the malware binary itself. The resulting package is uploaded directly to the Microsoft Defender portal, where it can be downloaded and submitted to a sandbox without an analyst ever needing to remote into the host. This is the standard, supported method to obtain a full artifact set for deep analysis.
- ✗
Run a live response session and manually download the file.
Why it's wrong here
Live response sessions facilitate interactive command-line investigation and real-time remediation on a remote endpoint. This method is used when an analyst needs to execute arbitrary scripts or inspect volatile memory during an active incident. However, the entity page provides a specific 'Collect file' action that automates the retrieval of forensic artifacts directly into the Microsoft 365 Defender portal, fulfilling the requirement to obtain a copy for sandboxing without manual command execution.
- ✗
Use the 'Add indicator' to allow the file and then collect.
Why it's wrong here
Adding an allow indicator for the file creates a custom intelligence rule that tells Defender for Endpoint to suppress alerts or detections matching that file hash or path. It does not perform any data retrieval; the subsequent 'collect' would have to be a separate action and would have run equally well without the indicator. Moreover, allowing a file that may be malicious can actively hinder detection and is a security misconfiguration, not a forensic collection step.
- ✗
Use the 'Device isolation' action to isolate again with different settings.
Why it's wrong here
Device isolation is a containment action that disconnects the affected machine from the network—either fully or selectively—to prevent lateral movement or command-and-control communication. It does not capture, package, or upload any files from the device, so rerunning it with modified settings cannot produce a forensic artifact set. To collect evidence for sandboxing, you must run a collection action or use a live response session to pull specific files.
Go deeper
Related to this question
About these practice questions
One of 209 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.