SC-200 Respond to security incidents Practice Question
You are responding to an incident where a malicious PowerShell script was executed on multiple endpoints. You need to collect the script content from the affected devices for analysis. What should you use?
⚠ Common exam trap
Test-takers frequently confuse Microsoft Defender for Cloud Apps activity logs with endpoint-level forensic data, assuming cloud logs contain script execution details, when in fact they only track cloud service interactions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint live response
Microsoft Defender for Endpoint live response (Option B) is the correct tool because it provides a remote shell connection to an endpoint, allowing you to collect the malicious PowerShell script content directly from the device's file system or memory. This is essential for forensic analysis when a script has been executed, as you can use commands like `Get-Content` or `Get-File` to retrieve the script file. Other options lack the direct, real-time access needed to extract script content from affected endpoints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud Apps activity logs
Why it's wrong here
Microsoft Defender for Cloud Apps activity logs record user sign-ins, app usage, and file activities, but they do not capture host-level process execution or the content of PowerShell scripts run on a device. These logs might show that a user accessed a suspicious site or downloaded a file, yet they lack the forensic detail needed to retrieve an executed malicious script. To recover script content, you need direct endpoint access, not cloud app telemetry.
- ✓
Microsoft Defender for Endpoint live response
Why this is correct
Microsoft Defender for Endpoint Live Response is the correct choice because it provides a remote, real-time shell for a compromised device. You can initiate a session from the MDE portal, run PowerShell commands, execute a script from the library, collect forensic artifacts, and retrieve the malicious script file for analysis. This interactive capability allows you to inspect the exact script content, confirm its behavior, and gather evidence directly from the endpoint.
- ✗
Microsoft Purview eDiscovery
Why it's wrong here
Microsoft Purview eDiscovery focuses on legal hold, in-place search, and export of content from Exchange, SharePoint, Teams, and OneDrive. It is designed for compliance and litigation, not for incident response on a live endpoint. While eDiscovery may locate emails or documents mentioning a script, it cannot execute commands, inspect processes, or pull the malicious PowerShell file from a compromised host's local file system.
- ✗
Azure Automation runbook
Why it's wrong here
Azure Automation runbooks execute PowerShell scripts within an isolated Azure sandbox or on hybrid workers, but they are built for scheduled or triggered automation, not interactive incident response. A runbook cannot attach to an already running compromised session, collect live memory/process details, or retrieve a malicious script from a specific endpoint's disk. Using a runbook would miss critical forensic evidence that Live Response can capture in real time.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.