SC-200 Respond to security incidents Practice Question
An incident in Microsoft Defender XDR shows a device with high severity alert: 'Suspicious PowerShell command line.' The device is currently isolated from the network. What is the best next step to investigate the alert?
⚠ Common exam trap
SC-200 often tests whether candidates understand that isolation is a containment step and that live response — not restoring connectivity or running a generic AV scan — is the correct investigative action on an isolated device.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a live response session on the device.
Running a live response session on the isolated device lets the analyst execute commands, collect forensic artifacts (process list, network connections, file hashes), and investigate the suspicious PowerShell activity without restoring network connectivity. This is the recommended next step in Microsoft Defender XDR when a device is already isolated, because live response provides direct, interactive access for evidence gathering. It preserves containment while enabling deeper investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Review the device timeline for related alerts.
Why it's wrong here
Reviewing the device timeline provides a chronological view of alerts and events, but it is a passive read-only activity that does not allow direct interaction with the endpoint. It cannot collect volatile evidence, kill malicious processes, or run investigative scripts in real time. As an incident responder, you need an active channel to gather forensic data and contain the threat immediately.
- ✓
Run a live response session on the device.
Why this is correct
Running a live response session on the device establishes an interactive, remote shell through the Microsoft Defender for Endpoint management plane. It enables the incident responder to execute PowerShell scripts, collect forensic artifacts such as memory, registry, and files, and apply remediation actions directly on the endpoint. Crucially, this can be done even while the device remains isolated, because the live response channel uses an outbound HTTPS connection to the cloud service.
- ✗
Restore network connectivity to allow the device to communicate with the cloud for analysis.
Why it's wrong here
Restoring network connectivity would re-expose the compromised device to untrusted networks, allowing the threat to communicate with command-and-control servers or propagate laterally to other hosts. Isolation is a deliberate containment measure and should stay in place until the investigation is complete. Live response does not require normal connectivity; it operates over an outbound management pipeline that remains available in isolation, so restoring connectivity is both unnecessary and dangerous.
- ✗
Initiate a full antivirus scan on the device.
Why it's wrong here
A full antivirus scan relies on signature databases and heuristic rules, which often miss fileless attacks, PowerShell-backed malware, and in-memory or kernel-level threats. It also does not provide the capability to inspect live processes, collect memory dumps, or perform adversarial response. Running a scan without an interactive investigation may trigger malicious behavior or allow malware to hide. It is a supplementary step rather than a first-responder action.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.