SC-200 Respond to security incidents Practice Question
During a security incident response, you need to collect forensic evidence from a Windows 10 device that is suspected to be compromised. The device is not domain-joined and is located in a remote office. You have remote administrative access. Which Microsoft 365 tool should you use to acquire a memory dump of the device?
⚠ Common exam trap
The trap is confusing forensic acquisition with management or eDiscovery tools—candidates pick Intune or Purview because they sound like they handle devices or data, but only Defender for Endpoint provides live response memory capture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint includes live response and the ability to collect forensic artifacts, including memory dumps, from onboarded devices. It supports remote acquisition from non-domain-joined Windows 10 devices as long as they are onboarded and you have the appropriate permissions. Sentinel, Purview eDiscovery, and Intune do not provide memory dump acquisition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel aggregates and analyses log data for detection and investigation; it has no agent capability to capture a live memory image from an endpoint. Sentinel is correct when the task is correlating signals, building analytics rules or triaging alerts across sources.
- ✗
Microsoft Purview eDiscovery
Why it's wrong here
Microsoft Purview eDiscovery collects mailbox, SharePoint and Teams content for legal hold and review, not volatile memory from an endpoint. It is the right tool when the requirement is identifying, preserving and exporting custodial documents for litigation or regulatory investigation.
- ✗
Microsoft Intune
Why it's wrong here
Intune manages device configuration and compliance; it cannot remotely capture a live memory image from a non-domain-joined endpoint. Intune is the right choice for enrolling devices, deploying policies and running remediation scripts, not for forensic acquisition during incident response.
- ✓
Microsoft Defender for Endpoint
Why this is correct
Microsoft Defender for Endpoint's live response feature provides a remote shell to the non-domain-joined Windows 10 device, where the memory dump can be captured using its built-in commands. This satisfies the remote acquisition constraint without physical access or domain membership.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.