SC-200 Respond to security incidents Practice Question
During an incident response, you need to collect forensic evidence from a compromised Windows device using Microsoft Defender for Endpoint live response. Which command should you use to gather running processes?
⚠ Common exam trap
SC-200 often tests whether candidates confuse standard Windows CLI commands (dir, netstat, reg query) with Defender for Endpoint live response's purpose-built command set, so candidates must memorise the live response command inventory rather than assume familiar OS tools are available.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
processes
The `processes` command in Microsoft Defender for Endpoint live response enumerates all currently running processes on the target device, returning details such as PID, name, and user context. It is one of the built-in live response commands specifically designed for forensic triage and incident investigation without needing to install third-party tooling. This makes it the correct choice for gathering running process evidence during an active incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
dir
Why it's wrong here
'dir' lists directory contents, returning filenames rather than process metadata such as PID, parent, or command line. It is the right command when enumerating files in a folder during triage, but forensic process collection requires Defender's 'processes' command.
- ✗
reg query
Why it's wrong here
'reg query' reads registry keys and values, useful for persistence artefacts such as Run keys or services. It returns no process list, so it cannot satisfy the requirement to gather running processes, which the live response 'processes' command provides.
- ✗
netstat
Why it's wrong here
'netstat' enumerates network connections and listening ports, not running processes; it suits identifying active connections or suspicious remote endpoints during triage. Process enumeration for forensic evidence requires the live response 'processes' command, which returns PID, name, and path.
- ✓
processes
Why this is correct
The 'processes' command enumerates running processes on the target device, returning process names, IDs, and related details. This satisfies the forensic requirement to capture volatile evidence of active processes before the compromised Windows host is remediated or shut down.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.