Courseiva

SC-200 Respond to security incidents Practice Question

During an incident response, you need to collect forensic data from Microsoft Defender for Endpoint (MDE) on a remote device that is currently offline. What is the best approach?

⚠ Common exam trap

It's easy for candidates to assume MDE can collect forensic data from a cloud store or via scheduled scans, but MDE's live response is the only native method for on-demand forensic collection from a remote device, and it requires the device to be online.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Initiate a live response session when the device comes online

When a device is offline, Microsoft Defender for Endpoint cannot establish a live response session because the device must be connected to the MDE service to execute commands. Initiating a live response session when the device comes online is the best approach because it allows you to run forensic collection commands (e.g., 'getfile', 'run') directly on the device via the MDE API, without requiring manual intervention or additional infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Initiate a live response session when the device comes online

    Why this is correct

    Live response in Microsoft Defender for Endpoint is the correct forensic data collection method because it provides an interactive, audited remote shell on the device. Once the device is online, you can run built-in commands such as 'collect' to capture evidence like running processes, registry data, event logs, and sensitive files in a structured package. Unlike manual methods, this session uses Microsoft's authorized API and records all commands for chain of custody, making it the preferred incident-response approach.

  • ✗

    Wait until the device is online and then collect manually

    Why it's wrong here

    Merely waiting and collecting manually relies on ad-hoc actions like RDP or external utilities, which are slow and inconsistent. Manual collection is error-prone because it depends on the responder to remember every artifact, and it does not automatically preserve a verifiable audit trail. In contrast, live response is a purpose-built, scriptable, and permission-controlled tool, so waiting without leveraging it sacrifices efficiency and forensic rigor.

  • ✗

    Run a remotely scheduled antivirus scan

    Why it's wrong here

    A remotely scheduled antivirus scan is designed to detect and remediate malware, not to capture forensic artifacts for investigation. Scanning actively touches the filesystem, may quarantine or delete malicious files, and can modify metadata such as last-access timestamps, compromising evidentiary integrity. Forensic collection requires passive, preservation-focused methods like live response's 'collect' command, which copy artifacts non-destructively rather than alter system state.

  • ✗

    Collect the data from the device's cloud store

    Why it's wrong here

    Microsoft Defender for Endpoint's cloud store contains only a limited set of telemetry and uploaded alerts, not a complete record of local forensic artifacts. Critical evidence such as full memory dumps, registry hives, or event logs that were never forwarded remain unavailable in the cloud. The cloud store is useful for correlated detections, but it cannot substitute for directly collecting endpoint data via a live response session once the device is online.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.