Courseiva

SC-200 Respond to security incidents Practice Question

You are responding to an incident where a user's device may be compromised. You need to collect forensic data from the device using Microsoft Defender for Endpoint. Which action should you take?

⚠ Common exam trap

Watch out — candidates often confuse 'Initiate Live Response' with forensic data collection because it offers interactive access, but the question specifically asks for a method to 'collect forensic data' in a packaged format, which only 'Collect investigation package' provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Collect investigation package

The 'Collect investigation package' action in Microsoft Defender for Endpoint is specifically designed to gather forensic data—such as registry hives, event logs, memory dumps, and disk images—from a device for offline analysis. This is the correct choice because the question explicitly asks to collect forensic data, and this action packages all relevant artifacts into a single .zip file for detailed examination.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Isolate device

    Why it's wrong here

    Isolating a device in Microsoft Defender for Endpoint restricts both inbound and outbound network traffic to halt lateral movement, but that containment step does not produce any forensic artifacts for the analyst. The investigation package is the separate, dedicated action that gathers the actual evidence. Selecting isolation first would address containment, not satisfy the requirement to collect data for the investigation.

  • ✗

    Initiate Live Response

    Why it's wrong here

    Live Response opens an interactive remote shell on the device, allowing an analyst to issue commands and download specific files in real time. It is not the same as the automated 'Collect investigation package' action, which bundles registry hives, event logs, processes, services, and other forensic artifacts into a single package. Live Response is useful for guided triage and hunting, but it relies on manual operator interaction rather than performing a comprehensive, standardized evidence collection.

  • ✓

    Collect investigation package

    Why this is correct

    The 'Collect investigation package' action in Microsoft Defender for Endpoint is the correct choice because it automatically assembles a ZIP file containing forensic data from the device, including registry entries, event logs, loaded modules, network connections, and running processes. This artifact is specifically designed for deep investigation and can be downloaded by the analyst for offline analysis. It is a built-in response action that captures the full evidentiary picture needed to determine the scope and origin of the incident.

  • ✗

    Run antivirus scan

    Why it's wrong here

    Running an antivirus scan is primarily a mitigation and detection measure that identifies malware and attempts to remediate it, but it does not preserve or collect comprehensive forensic evidence such as registry persistence keys, prefetch files, or memory artifacts. A scan can even be evaded by fileless or living-off-the-land techniques, and it lacks the investigative depth of an investigation package. Therefore, while it has a role in eradication, it is not an evidence-collection action.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.