Courseiva

SC-200 Respond to security incidents Practice Question

During an incident response, you need to collect a forensic image of a Windows 10 device managed by Microsoft Intune. Which Microsoft Defender XDR feature should you use?

⚠ Common exam trap

Many exam-takers confuse the forensic imaging requirement with a general log collection or eDiscovery tool, overlooking that Live Response is the only option that provides direct, interactive remote access to a managed endpoint for acquiring disk or memory artifacts during an active incident.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Endpoint Live Response

Microsoft Defender for Endpoint Live Response (Option C) is the correct feature because it provides a remote shell connection to a Windows 10 device, allowing an incident responder to collect a forensic image by running commands such as `getfile` or `putfile` to acquire disk or memory artifacts. This capability is specifically designed for live incident response on Intune-managed endpoints, enabling acquisition of forensic data without requiring physical access or pre-staged imaging tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps acts as a cloud access security broker (CASB), focusing on shadow IT discovery, policy enforcement, and data-loss prevention across SaaS/PaaS applications. It cannot execute commands on or acquire an endpoint's memory, registry, or files. For live forensic collection from an OS, you need an endpoint agent with remote shell capabilities, which Cloud Apps does not have.

  • ✗

    Microsoft Purview eDiscovery

    Why it's wrong here

    Microsoft Purview eDiscovery is designed for legal investigations and compliance, performing content search, in-place hold, and export of documents across Exchange, SharePoint, Teams, and OneDrive through Microsoft Graph. It preserves and collects data stored in cloud workloads rather than operating-system artifacts such as the registry, running processes, or memory. It cannot obtain a live forensic snapshot of an endpoint's disk state or perform remote response actions.

  • ✓

    Microsoft Defender for Endpoint Live Response

    Why this is correct

    Microsoft Defender for Endpoint Live Response provides an interactive, remote shell on an onboarded endpoint, enabling incident responders to run built-in, PowerShell, or Python commands. It supports collecting files (collectfile), viewing processes and network connections, and running forensic scripts to extract memory, registry, or disk artifacts. This is the correct tool for live forensic data collection directly from the machine, using the Defender for Endpoint sensor as the transport.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM/SOAR that aggregates logs from many sources, including Defender for Endpoint, and uses analytics rules and playbooks for detection and automated response. It has no agent installed on user devices and cannot execute commands or extract forensic images from a live endpoint. Its role is to correlate and surface alerts, not to provide remote OS-level forensic acquisition.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.