SC-200 Respond to security incidents Practice Question
During an incident response, a forensic investigator needs to collect a memory dump from a compromised Windows server that is still running. The server has Microsoft Defender for Endpoint installed but is not connected to the internet. Which method should the investigator use?
⚠ Common exam trap
SC-200 often tests the misconception that cloud-based security tools like Microsoft 365 Defender portal or Live Response can be used on devices without internet connectivity, but they require the device to be online and connected to the service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Sysinternals Suite to capture a memory dump locally
The server is not connected to the internet, which means cloud-based tools like Microsoft 365 Defender portal and Live Response cannot be used. Sysinternals Suite, specifically tools like ProcDump or RAMMap, can be run locally to capture a memory dump without requiring internet connectivity. This is the only option that works in an offline scenario, as it relies on local execution rather than cloud services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Collect a system memory snapshot from the Microsoft 365 Defender portal
Why it's wrong here
The Microsoft 365 Defender portal is a cloud-based management console that issues device actions through the Defender for Endpoint agent over a live network connection. For an offline server, the portal cannot communicate with the sensor, so a memory snapshot request will never reach the device and no data can be collected. Moreover, the portal has no out-of-band mechanism to retrieve memory from a disconnected host, making it unsuitable for offline forensic acquisition.
- ✗
Use Live Response to run a memory dump collector on the device
Why it's wrong here
Live Response is a remote PowerShell-style session that runs commands on an endpoint, but it depends on an active channel between the device and Microsoft Defender for Endpoint, typically over HTTPS. When the machine is offline, the Live Response session cannot be established, and any memory dump collector you launch would have nothing to execute because the device is unreachable. Even if a session were somehow available, the command would fail due to lack of connectivity.
- ✗
Initiate a memory dump from the Microsoft Defender for Endpoint portal
Why it's wrong here
The 'Collect memory dump' action in the Microsoft Defender for Endpoint portal is a remote machine action that sends a command to the device's MDE sensor; if the sensor is offline, the action is just queued in the portal and never executes. The portal requires the device to be online and to have a healthy agent communication channel, otherwise no dump is written locally. This action is fundamentally a cloud-initiated collection, so it cannot be used as a local forensic technique on an isolated server.
- ✓
Use Sysinternals Suite to capture a memory dump locally
Why this is correct
Sysinternals Suite tools such as procdump execute natively on the local computer, using Windows internals (e.g., MiniDumpWriteDump) to capture process memory without relying on any network connection. This makes them ideal for an offline server because a forensic examiner can copy the tool to the machine via removable media and run it from an elevated command prompt to save a .dmp file to local disk. The resulting dump can then be analyzed on a separate workstation, preserving volatile evidence on the original host.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a security incident response, you need to collect forensic evidence from a Windows 10 device that is suspected to be compromised. The device is not domain-joined and is located in a remote office. You have remote administrative access. Which Microsoft 365 tool should you use to acquire a memory dump of the device?
easy- A.Microsoft Sentinel
- B.Microsoft Purview eDiscovery
- C.Microsoft Intune
- ✓ D.Microsoft Defender for Endpoint
Why D: Microsoft Defender for Endpoint includes live response and the ability to collect forensic artifacts, including memory dumps, from onboarded devices. It supports remote acquisition from non-domain-joined Windows 10 devices as long as they are onboarded and you have the appropriate permissions. Sentinel, Purview eDiscovery, and Intune do not provide memory dump acquisition.
Variation 2. During an incident response, you need to collect a forensic image of a Windows 10 device managed by Microsoft Intune. Which Microsoft Defender XDR feature should you use?
easy- A.Microsoft Defender for Cloud Apps
- B.Microsoft Purview eDiscovery
- ✓ C.Microsoft Defender for Endpoint Live Response
- D.Microsoft Sentinel
Why C: Microsoft Defender for Endpoint Live Response (Option C) is the correct feature because it provides a remote shell connection to a Windows 10 device, allowing an incident responder to collect a forensic image by running commands such as `getfile` or `putfile` to acquire disk or memory artifacts. This capability is specifically designed for live incident response on Intune-managed endpoints, enabling acquisition of forensic data without requiring physical access or pre-staged imaging tools.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.