Courseiva

Collecting Forensic Evidence from Windows with Microsoft Defender for Endpoint

Your company uses Microsoft Defender for Endpoint. A device shows signs of compromise with suspicious PowerShell execution. You need to collect forensic evidence before performing remediation. Which action should you use?

Quick Answer

The answer is to collect the investigation package. This action is correct because it gathers a comprehensive set of forensic evidence from the Windows device—including files, processes, registry keys, and memory artifacts—directly addressing the need to capture data from suspicious PowerShell execution before any remediation steps alter the system state. On the Microsoft Security Operations Analyst SC-200 exam, this question tests your ability to distinguish between investigative and remedial actions within Microsoft Defender for Endpoint; a common trap is confusing the investigation package with live response, but remember that live response is for real-time interactive analysis, not for collecting a full forensic snapshot. The key memory tip is “collect first, contain later”—the investigation package preserves the crime scene, while antivirus scans, isolation, and live response are for after evidence is secured.

⚠ Common exam trap

SC-200 often tests the order of incident response actions — candidates pick 'Isolate the device' because it sounds like the most urgent step, but the question specifically asks for evidence collection before remediation, making 'Collect investigation package' the correct choice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Collect investigation package.

In Microsoft Defender for Endpoint, the 'Collect investigation package' action gathers a forensic snapshot of the device — including running processes, network connections, autoruns, scheduled tasks, and recent files — without altering the system state. This is the correct first step when you need to preserve evidence before remediation, because it captures volatile data that would be lost if you isolated or remediated the device. Isolation and live response are separate actions that serve different purposes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Isolate the device from the network.

    Why it's wrong here

    Isolating the device blocks attacker command-and-control but also severs the management channel needed to pull forensic artefacts, and it preserves no volatile data itself. It is tempting as immediate containment, and would be correct when stopping active exfiltration takes priority over evidence gathering.

  • ✗

    Run a full antivirus scan.

    Why it's wrong here

    A full antivirus scan remediates detected threats and alters filesystem state, destroying volatile artefacts such as running processes and network connections before evidence is captured. It is tempting as a containment step, but it is the correct choice only after forensic collection is complete.

  • ✓

    Collect investigation package.

    Why this is correct

    Collecting the investigation package gathers volatile forensic artefacts — running processes, scheduled tasks, network connections and autorun entries — from the compromised device before remediation alters them. This satisfies the stem's requirement to preserve evidence first, whereas isolating or remediating the device would destroy the volatile data needed for later analysis.

  • ✗

    Initiate a live response session.

    Why it's wrong here

    Live response provides remote shell access to run forensic commands and pull files, but the question asks which action collects evidence; live response is the correct answer here, so this option is not the distractor. It would be right when interactive investigation is needed.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

5 more ways this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a security incident, you need to collect forensic evidence from a compromised Windows device. Which Microsoft Defender for Endpoint action should you use to collect a memory dump?

medium
  • ✓ A.Initiate Live Response
  • B.Isolate device
  • C.Collect investigation package
  • D.Run antivirus scan

Why A: Live Response lets an analyst connect to the device and run a memory-acquisition tool/script to capture a memory dump. The 'Collect investigation package' action gathers artifacts such as autoruns, processes, network connections, and prefetch files, but it does not include a full memory dump.

Variation 2. During a security incident response, you need to collect forensic evidence from a Windows 10 device that is suspected to be compromised. The device is not domain-joined and is located in a remote office. You have remote administrative access. Which Microsoft 365 tool should you use to acquire a memory dump of the device?

easy
  • A.Microsoft Sentinel
  • B.Microsoft Purview eDiscovery
  • C.Microsoft Intune
  • ✓ D.Microsoft Defender for Endpoint

Why D: Microsoft Defender for Endpoint includes live response and the ability to collect forensic artifacts, including memory dumps, from onboarded devices. It supports remote acquisition from non-domain-joined Windows 10 devices as long as they are onboarded and you have the appropriate permissions. Sentinel, Purview eDiscovery, and Intune do not provide memory dump acquisition.

Variation 3. During an incident response, you need to collect a forensic image of a Windows 10 device managed by Microsoft Intune. Which Microsoft Defender XDR feature should you use?

easy
  • A.Microsoft Defender for Cloud Apps
  • B.Microsoft Purview eDiscovery
  • ✓ C.Microsoft Defender for Endpoint Live Response
  • D.Microsoft Sentinel

Why C: Microsoft Defender for Endpoint Live Response (Option C) is the correct feature because it provides a remote shell connection to a Windows 10 device, allowing an incident responder to collect a forensic image by running commands such as `getfile` or `putfile` to acquire disk or memory artifacts. This capability is specifically designed for live incident response on Intune-managed endpoints, enabling acquisition of forensic data without requiring physical access or pre-staged imaging tools.

Variation 4. During an incident response, a forensic investigator needs to collect a memory dump from a compromised Windows server that is still running. The server has Microsoft Defender for Endpoint installed but is not connected to the internet. Which method should the investigator use?

hard
  • A.Collect a system memory snapshot from the Microsoft 365 Defender portal
  • B.Use Live Response to run a memory dump collector on the device
  • C.Initiate a memory dump from the Microsoft Defender for Endpoint portal
  • ✓ D.Use Sysinternals Suite to capture a memory dump locally

Why D: The correct answer is D because the server is not connected to the internet, which means cloud-based tools like Microsoft 365 Defender portal and Live Response cannot be used. Sysinternals Suite, specifically tools like ProcDump or RAMMap, can be run locally to capture a memory dump without requiring internet connectivity. This is the only option that works in an offline scenario, as it relies on local execution rather than cloud services.

Variation 5. Which THREE are valid methods to collect forensic evidence from a compromised Windows machine during incident response in Microsoft Defender XDR? (Choose three.)

hard
  • A.Reset the device to a clean state
  • ✓ B.Collect a memory dump from the device using Live Response
  • C.Perform a full disk image using Microsoft Defender for Endpoint
  • ✓ D.Run Live Response commands to collect files and run scripts
  • ✓ E.Export Windows Event Logs using Live Response

Why B: Options B, D, and E are correct: Live Response allows script execution and file collection; collecting a memory dump captures volatile evidence necessary for forensic analysis; exporting Windows Event Logs provides a timeline of events. Option A is incorrect because resetting the device destroys evidence instead of preserving it. Option C is incorrect because full disk imaging is not natively supported in Microsoft Defender XDR; it requires external tools.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.