Courseiva

SC-200 Respond to security incidents Practice Question

You are responding to an incident where a malicious PowerShell script was executed on multiple endpoints. You need to collect the script content from the affected devices for analysis. What should you use?

⚠ Common exam trap

Test-takers frequently confuse Microsoft Defender for Cloud Apps activity logs with endpoint-level forensic data, assuming cloud logs contain script execution details, when in fact they only track cloud service interactions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Endpoint live response

Microsoft Defender for Endpoint live response (Option B) is the correct tool because it provides a remote shell connection to an endpoint, allowing you to collect the malicious PowerShell script content directly from the device's file system or memory. This is essential for forensic analysis when a script has been executed, as you can use commands like `Get-Content` or `Get-File` to retrieve the script file. Other options lack the direct, real-time access needed to extract script content from affected endpoints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Cloud Apps activity logs

    Why it's wrong here

    Microsoft Defender for Cloud Apps activity logs record user sign-ins, app usage, and file activities, but they do not capture host-level process execution or the content of PowerShell scripts run on a device. These logs might show that a user accessed a suspicious site or downloaded a file, yet they lack the forensic detail needed to retrieve an executed malicious script. To recover script content, you need direct endpoint access, not cloud app telemetry.

  • ✓

    Microsoft Defender for Endpoint live response

    Why this is correct

    Microsoft Defender for Endpoint Live Response is the correct choice because it provides a remote, real-time shell for a compromised device. You can initiate a session from the MDE portal, run PowerShell commands, execute a script from the library, collect forensic artifacts, and retrieve the malicious script file for analysis. This interactive capability allows you to inspect the exact script content, confirm its behavior, and gather evidence directly from the endpoint.

  • ✗

    Microsoft Purview eDiscovery

    Why it's wrong here

    Microsoft Purview eDiscovery focuses on legal hold, in-place search, and export of content from Exchange, SharePoint, Teams, and OneDrive. It is designed for compliance and litigation, not for incident response on a live endpoint. While eDiscovery may locate emails or documents mentioning a script, it cannot execute commands, inspect processes, or pull the malicious PowerShell file from a compromised host's local file system.

  • ✗

    Azure Automation runbook

    Why it's wrong here

    Azure Automation runbooks execute PowerShell scripts within an isolated Azure sandbox or on hybrid workers, but they are built for scheduled or triggered automation, not interactive incident response. A runbook cannot attach to an already running compromised session, collect live memory/process details, or retrieve a malicious script from a specific endpoint's disk. Using a runbook would miss critical forensic evidence that Live Response can capture in real time.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.