SC-200 Respond to security incidents Practice Question
During an incident response, you need to collect a forensic image of a Windows 10 device managed by Microsoft Intune. Which Microsoft Defender XDR feature should you use?
⚠ Common exam trap
Many exam-takers confuse the forensic imaging requirement with a general log collection or eDiscovery tool, overlooking that Live Response is the only option that provides direct, interactive remote access to a managed endpoint for acquiring disk or memory artifacts during an active incident.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint Live Response
Microsoft Defender for Endpoint Live Response (Option C) is the correct feature because it provides a remote shell connection to a Windows 10 device, allowing an incident responder to collect a forensic image by running commands such as `getfile` or `putfile` to acquire disk or memory artifacts. This capability is specifically designed for live incident response on Intune-managed endpoints, enabling acquisition of forensic data without requiring physical access or pre-staged imaging tools.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps acts as a cloud access security broker (CASB), focusing on shadow IT discovery, policy enforcement, and data-loss prevention across SaaS/PaaS applications. It cannot execute commands on or acquire an endpoint's memory, registry, or files. For live forensic collection from an OS, you need an endpoint agent with remote shell capabilities, which Cloud Apps does not have.
- ✗
Microsoft Purview eDiscovery
Why it's wrong here
Microsoft Purview eDiscovery is designed for legal investigations and compliance, performing content search, in-place hold, and export of documents across Exchange, SharePoint, Teams, and OneDrive through Microsoft Graph. It preserves and collects data stored in cloud workloads rather than operating-system artifacts such as the registry, running processes, or memory. It cannot obtain a live forensic snapshot of an endpoint's disk state or perform remote response actions.
- ✓
Microsoft Defender for Endpoint Live Response
Why this is correct
Microsoft Defender for Endpoint Live Response provides an interactive, remote shell on an onboarded endpoint, enabling incident responders to run built-in, PowerShell, or Python commands. It supports collecting files (collectfile), viewing processes and network connections, and running forensic scripts to extract memory, registry, or disk artifacts. This is the correct tool for live forensic data collection directly from the machine, using the Defender for Endpoint sensor as the transport.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM/SOAR that aggregates logs from many sources, including Defender for Endpoint, and uses analytics rules and playbooks for detection and automated response. It has no agent installed on user devices and cannot execute commands or extract forensic images from a live endpoint. Its role is to correlate and surface alerts, not to provide remote OS-level forensic acquisition.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.