Courseiva

SC-200 Respond to security incidents Practice Question

During a security incident response, you need to collect forensic evidence from a Windows 10 device that is suspected to be compromised. The device is not domain-joined and is located in a remote office. You have remote administrative access. Which Microsoft 365 tool should you use to acquire a memory dump of the device?

⚠ Common exam trap

The trap is confusing forensic acquisition with management or eDiscovery tools—candidates pick Intune or Purview because they sound like they handle devices or data, but only Defender for Endpoint provides live response memory capture.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Endpoint

Microsoft Defender for Endpoint includes live response and the ability to collect forensic artifacts, including memory dumps, from onboarded devices. It supports remote acquisition from non-domain-joined Windows 10 devices as long as they are onboarded and you have the appropriate permissions. Sentinel, Purview eDiscovery, and Intune do not provide memory dump acquisition.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel aggregates and analyses log data for detection and investigation; it has no agent capability to capture a live memory image from an endpoint. Sentinel is correct when the task is correlating signals, building analytics rules or triaging alerts across sources.

  • ✗

    Microsoft Purview eDiscovery

    Why it's wrong here

    Microsoft Purview eDiscovery collects mailbox, SharePoint and Teams content for legal hold and review, not volatile memory from an endpoint. It is the right tool when the requirement is identifying, preserving and exporting custodial documents for litigation or regulatory investigation.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Intune manages device configuration and compliance; it cannot remotely capture a live memory image from a non-domain-joined endpoint. Intune is the right choice for enrolling devices, deploying policies and running remediation scripts, not for forensic acquisition during incident response.

  • ✓

    Microsoft Defender for Endpoint

    Why this is correct

    Microsoft Defender for Endpoint's live response feature provides a remote shell to the non-domain-joined Windows 10 device, where the memory dump can be captured using its built-in commands. This satisfies the remote acquisition constraint without physical access or domain membership.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.