SC-200 Respond to security incidents Practice Question
During an incident response, you need to collect a memory dump from a compromised Windows 10 device managed by Microsoft Defender for Endpoint. Which action should you take in the Microsoft Defender XDR portal?
⚠ Common exam trap
Watch out — candidates often confuse 'Live Response' with 'automated investigation' or 'custom detection scripts', assuming those can perform memory collection, when in fact only the explicit 'memdump' command within a Live Response session achieves this forensic task.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Initiate a Live Response session and run the 'memdump' command
To collect a memory dump from a compromised Windows 10 device managed by Microsoft Defender for Endpoint, you must initiate a Live Response session and run the 'memdump' command. Live Response provides a remote shell that allows forensic commands like 'memdump' to capture the full memory contents of the target machine, which is essential for analyzing volatile data during incident response. Other options, such as custom detection scripts or automated investigations, do not directly support memory acquisition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a custom detection script
Why it's wrong here
Custom detection scripts in Microsoft Defender for Endpoint are configured to run automatically when specific detection rules trigger, not interactively on demand for a chosen device. They are designed to hunt for indicators of compromise rather than capture volatile forensic artifacts. Therefore, they cannot be used to collect a memory dump during an incident.
- ✓
Initiate a Live Response session and run the 'memdump' command
Why this is correct
Initiate a Live Response session in Microsoft Defender for Endpoint to get a remote shell on the device, allowing you to execute built-in commands such as memdump. The memdump command captures a full copy of the system's physical memory, which is essential for analyzing in-memory threats like process injection and credential theft. This is the correct method for on-demand memory acquisition.
- ✗
Execute a Power Automate flow to collect memory
Why it's wrong here
Power Automate flows orchestrate automated workflows across cloud services, but they lack the ability to execute privileged forensic commands directly on an endpoint's operating system. Even though flows can trigger API actions, Microsoft does not provide a connector that performs raw memory acquisition like Live Response's memdump. Thus, a flow would not collect the actual memory dump needed for incident analysis.
- ✗
Start a full antivirus scan
Why it's wrong here
A full antivirus scan enumerates files, boot sectors, and active processes to identify known malware signatures, but it does not snapshot the contents of physical memory. Memory dumps preserve volatile data such as unpacked malware threads and plaintext credentials that scans miss. Therefore, an AV scan is a malware detection tool, not a forensic collection method.
- ✗
Submit the device for automated investigation
Why it's wrong here
Automated investigations use pre-defined playbooks to triage alerts and take actions like isolating devices or deleting malicious files, but these playbooks do not include memory dump collection as a standard response action. Preserving volatile memory requires a deliberate, interactive step that automation may skip to avoid disrupting ongoing operations. Because of this, an automated investigation is unsuitable when you need a memory dump for evidence.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.