Courseiva

SC-200 Respond to security incidents Practice Question

You are responding to a security incident involving a user who clicked on a malicious link in an email. The link led to a website that downloaded a file to the user's device. Microsoft Defender for Endpoint (MDE) detected the file as malware and blocked it. However, the user reports that the device is running slowly. You need to verify if there are any remnants of the malware. Which action should you take?

⚠ Common exam trap

SC-200 often tests the instinct to 'nuke and pave' or run a generic AV scan — candidates overlook that live response is the targeted forensic tool for verifying remnants after a blocked infection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Initiate a live response session and run a PowerShell script to check for persistence mechanisms.

A live response session in Microsoft Defender for Endpoint lets you run remote investigative commands — including PowerShell scripts — directly on the device to enumerate persistence mechanisms such as Run keys, scheduled tasks, services, and WMI subscriptions. Since MDE already blocked the malware, the goal is to verify no remnants or persistence artifacts remain, and live response is the purpose-built tool for that forensic check.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Re-onboard the device to MDE to ensure it's fully managed.

    Why it's wrong here

    Re-onboarding the device to Microsoft Defender for Endpoint would only re-register the sensor and restore policy delivery; it does not perform any forensic analysis of the system. Since the device is already onboarded and reporting to MDE, this action is redundant and would not reveal persistence artifacts or explain slow performance. The goal here is to investigate remnants of the incident, not to change the device's management state.

  • ✗

    Run a full antivirus scan using Microsoft Defender Antivirus.

    Why it's wrong here

    Running a full antivirus scan with Microsoft Defender Antivirus is not appropriate because the malicious payload was already blocked before execution, so there may be no active malware signatures to detect. A scan primarily looks for known file-based threats and does not inspect memory, scheduled tasks, or registry persistence mechanisms that are often used by fileless and polymorphic malware. Additionally, the reported low performance could be caused by many non-malicious factors, and an AV scan would not provide the deep visibility needed to confirm whether any remnant of the attack remains.

  • ✓

    Initiate a live response session and run a PowerShell script to check for persistence mechanisms.

    Why this is correct

    Initiating a live response session on the endpoint and executing a PowerShell script is the correct action because it provides a remote, audited shell that can directly interrogate the system's persistence mechanisms. The script can enumerate Services, Run keys, scheduled tasks, WMI event subscriptions, and other autostart locations to determine whether the attacker left behind a way to re-enter. This aligns with MDE's incident response workflow, allowing you to collect evidence and remediate instantly without taking the device offline.

  • ✗

    Perform a full OS reinstall to ensure the device is clean.

    Why it's wrong here

    Performing a full OS reinstall is an extreme and destructive course of action that should only be used when no forensic value remains or when the system is so compromised that rebuilding is the only safe option. In this scenario, the malware was blocked and the device is still manageable, so a reimage would destroy potential evidence and unnecessarily disrupt the user's productivity. The correct approach is to first conduct a targeted investigation to determine if any remnants actually exist, and only then decide if reinstallation is warranted.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.