SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit.
```powershell
$params = @{
ActivityFunction = "Run"
ActionType = "RunAntiMalwareScan"
MachineId = "machine123"
Comment = "Scheduled scan"
}
Invoke-MDEDeviceAction @params
```Refer to the exhibit. You run the PowerShell command against Microsoft Defender for Endpoint. What is the result?
⚠ Common exam trap
A common mix-up: candidates confuse the `Start-MpScan` cmdlet with other Defender for Endpoint actions like investigation package collection or device isolation, because all are available under the 'Actions' menu in the portal, but each uses a distinct PowerShell cmdlet or API call.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An antivirus scan runs on the device.
The `Start-MpScan` cmdlet initiates a Microsoft Defender Antivirus scan on the device. The `-ScanType` parameter with value `QuickScan` specifies a quick scan of common malware locations, not a full scan. This is a direct antivirus action, not an investigation package collection, isolation, or Live Response session.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The investigation package is collected.
Why it's wrong here
Collecting an investigation package is a distinct Defender for Endpoint action that bundles device logs, event logs, and registry hives into a zip archive for offline analysis. The ActionType 'RunAntiMalwareScan' does not invoke artifact collection; it only instructs the antimalware engine to perform a scan. A separate command, such as 'New-InvestigationPackage', would be required.
- ✓
An antivirus scan runs on the device.
Why this is correct
The ActionType 'RunAntiMalwareScan' sends a command through the Defender for Endpoint sensor to the antimalware engine, instructing it to execute a scan on the endpoint. This is a non-interactive, one-time response action that can be a full or quick scan depending on device policy, with results reported back to the console. It does not require isolation or a Live Response session.
- ✗
The device is isolated from the network.
Why it's wrong here
Isolating a device is a separate ActionType (typically 'IsolateDevice') that severs network connectivity, while a scan is purely a local operation that runs with the device still connected. The 'RunAntiMalwareScan' action does not include any network-level changes. If isolation were intended, the cmdlet would reference 'IsolateDevice' or 'Start-DeviceIsolation'.
- ✗
A Live Response session is started.
Why it's wrong here
Live Response is an interactive, remote shell session for real-time forensic investigation, initiated with a dedicated cmdlet like 'Start-LiveResponse' or through the Defender console. Unlike a Live Response session, 'RunAntiMalwareScan' is a one-shot, non-interactive machine action that executes and terminates without establishing a session. The scan command does not leave an open channel or allow live commands.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.