Courseiva

SC-200 Respond to security incidents Practice Question

During an incident response, a SOC analyst identifies that a malicious PowerShell script was executed on multiple endpoints. The analyst needs to collect relevant files from all affected endpoints for further analysis. What should the analyst use?

⚠ Common exam trap

A common mix-up: candidates confuse Microsoft Sentinel's investigation graph (which visualizes relationships) with a tool that can actually collect files, or they may think cloud app investigation or eDiscovery can be used for endpoint file collection, when neither supports live endpoint access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Endpoint Live Response.

Microsoft Defender for Endpoint Live Response allows analysts to remotely connect to endpoints and collect files, run scripts, and perform forensic actions in real time. This is the correct tool for gathering malicious PowerShell scripts from multiple affected endpoints during incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Cloud Apps file investigation.

    Why it's wrong here

    Microsoft Defender for Cloud Apps file investigation is designed to analyze files stored within integrated cloud applications such as SharePoint, OneDrive, or Box via API connector queries. It does not deploy an agent to an endpoint and therefore has no capability to access the local file system or collect files directly from a compromised device. Its scope is cloud-native data governance and threat detection, not endpoint forensic acquisition.

  • ✗

    Microsoft Purview eDiscovery.

    Why it's wrong here

    Microsoft Purview eDiscovery is a compliance-oriented tool used for legal holds, content search, and export of data from Microsoft 365 workloads such as Exchange, SharePoint, and Teams. It lacks the ability to open a live shell, execute commands, or pull artifacts from an endpoint in real time. eDiscovery operates asynchronously against cloud repositories, making it unsuitable for time-sensitive incident response file collection from a host.

  • ✓

    Microsoft Defender for Endpoint Live Response.

    Why this is correct

    Microsoft Defender for Endpoint Live Response is the correct tool because it provides a secure, remote shell session to an endpoint that is onboarded to Microsoft Defender for Endpoint. Analysts can use Live Response commands like 'collect' to retrieve specific files, run forensic scripts, and inspect system artifacts in real time. It also supports a managed library of commands and can be restricted through RBAC roles, making it purpose-built for incident response file collection.

  • ✗

    Microsoft Sentinel incident investigation graph.

    Why it's wrong here

    Microsoft Sentinel's incident investigation graph visualizes relationships between alerts, entities, and activities using data already ingested into the SIEM. It does not have any direct connection to an endpoint's file system and cannot initiate file retrieval or command execution. Its purpose is to accelerate triage and correlation analysis, not to serve as a file collection mechanism during live response.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.