Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

Refer to the exhibit.
```powershell
$params = @{
  ActivityFunction = "Run"
  ActionType = "RunAntiMalwareScan"
  MachineId = "machine123"
  Comment = "Scheduled scan"
}
Invoke-MDEDeviceAction @params
```

Refer to the exhibit. You run the PowerShell command against Microsoft Defender for Endpoint. What is the result?

⚠ Common exam trap

A common mix-up: candidates confuse the `Start-MpScan` cmdlet with other Defender for Endpoint actions like investigation package collection or device isolation, because all are available under the 'Actions' menu in the portal, but each uses a distinct PowerShell cmdlet or API call.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An antivirus scan runs on the device.

The `Start-MpScan` cmdlet initiates a Microsoft Defender Antivirus scan on the device. The `-ScanType` parameter with value `QuickScan` specifies a quick scan of common malware locations, not a full scan. This is a direct antivirus action, not an investigation package collection, isolation, or Live Response session.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The investigation package is collected.

    Why it's wrong here

    Collecting an investigation package is a distinct Defender for Endpoint action that bundles device logs, event logs, and registry hives into a zip archive for offline analysis. The ActionType 'RunAntiMalwareScan' does not invoke artifact collection; it only instructs the antimalware engine to perform a scan. A separate command, such as 'New-InvestigationPackage', would be required.

  • ✓

    An antivirus scan runs on the device.

    Why this is correct

    The ActionType 'RunAntiMalwareScan' sends a command through the Defender for Endpoint sensor to the antimalware engine, instructing it to execute a scan on the endpoint. This is a non-interactive, one-time response action that can be a full or quick scan depending on device policy, with results reported back to the console. It does not require isolation or a Live Response session.

  • ✗

    The device is isolated from the network.

    Why it's wrong here

    Isolating a device is a separate ActionType (typically 'IsolateDevice') that severs network connectivity, while a scan is purely a local operation that runs with the device still connected. The 'RunAntiMalwareScan' action does not include any network-level changes. If isolation were intended, the cmdlet would reference 'IsolateDevice' or 'Start-DeviceIsolation'.

  • ✗

    A Live Response session is started.

    Why it's wrong here

    Live Response is an interactive, remote shell session for real-time forensic investigation, initiated with a dedicated cmdlet like 'Start-LiveResponse' or through the Defender console. Unlike a Live Response session, 'RunAntiMalwareScan' is a one-shot, non-interactive machine action that executes and terminates without establishing a session. The scan command does not leave an open channel or allow live commands.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.