Courseiva

SC-200 Respond to security incidents Practice Question

During an incident response, you need to collect forensic evidence from a compromised Windows device using Microsoft Defender for Endpoint live response. Which command should you use to gather running processes?

⚠ Common exam trap

SC-200 often tests whether candidates confuse standard Windows CLI commands (dir, netstat, reg query) with Defender for Endpoint live response's purpose-built command set, so candidates must memorise the live response command inventory rather than assume familiar OS tools are available.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

processes

The `processes` command in Microsoft Defender for Endpoint live response enumerates all currently running processes on the target device, returning details such as PID, name, and user context. It is one of the built-in live response commands specifically designed for forensic triage and incident investigation without needing to install third-party tooling. This makes it the correct choice for gathering running process evidence during an active incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    dir

    Why it's wrong here

    'dir' lists directory contents, returning filenames rather than process metadata such as PID, parent, or command line. It is the right command when enumerating files in a folder during triage, but forensic process collection requires Defender's 'processes' command.

  • ✗

    reg query

    Why it's wrong here

    'reg query' reads registry keys and values, useful for persistence artefacts such as Run keys or services. It returns no process list, so it cannot satisfy the requirement to gather running processes, which the live response 'processes' command provides.

  • ✗

    netstat

    Why it's wrong here

    'netstat' enumerates network connections and listening ports, not running processes; it suits identifying active connections or suspicious remote endpoints during triage. Process enumeration for forensic evidence requires the live response 'processes' command, which returns PID, name, and path.

  • ✓

    processes

    Why this is correct

    The 'processes' command enumerates running processes on the target device, returning process names, IDs, and related details. This satisfies the forensic requirement to capture volatile evidence of active processes before the compromised Windows host is remediated or shut down.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.