SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit.
$alert = Get-MpThreatDetection | Where-Object {$_.ThreatName -like "*Trojan*"}
if ($alert) {
Start-MpScan -ScanType QuickScan
}You are reviewing a PowerShell script used for automated response on a Windows 10 device managed by Microsoft Defender for Endpoint. What is the intended outcome of this script?
⚠ Common exam trap
A common mix-up: candidates assume the script performs remediation (option A) or updates signatures (option B) because those are common steps in response workflows, but the script only triggers a scan based on detection, not removal or update actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It triggers a quick scan if any Trojan detection exists.
The script checks for Trojan detections using Get-MpThreat with a threat category filter for Trojans. If any Trojan is found, it triggers Start-MpScan -ScanType QuickScan to perform a quick scan. This matches option C exactly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It removes all Trojan threats from the device.
Why it's wrong here
The script is only performing a detection and scan operation; it never calls a remediation cmdlet such as Remove-MpThreat or invokes an action like ThreatIDDefaultAction. Trojan removal would require either an explicit remediation step or the automatic remediation pipeline, neither of which is present in the described script. Therefore, stating that it removes all Trojan threats overstates the script's actual behavior.
- ✗
It updates the antimalware signatures and then performs a scan.
Why it's wrong here
No Update-MpSignature, Update-MpAntimalware, or similar definition-update cmdlet is invoked anywhere in the described flow. The script conditions its scan on existing Trojan detections, but it does not refresh the antimalware signatures before doing so. Relying on stale definitions could produce incomplete results, but that is not the behavior being described here—only the conditional quick scan occurs.
- ✓
It triggers a quick scan if any Trojan detection exists.
Why this is correct
The script includes a conditional statement that evaluates whether any Trojan threat detection is present, likely using Get-MpThreatDetection or Get-MpThreat with a filter for the Trojan threat category. When that condition is true, it executes Start-MpScan with the QuickScan parameter. Because the decision to run the quick scan depends directly on the presence of Trojan detections, the correct characterization is that it triggers a quick scan if any Trojan detection exists.
- ✗
It configures Windows Defender to exclude Trojan files.
Why it's wrong here
There is no use of Add-MpPreference to create path, extension, or process exclusions, and excluding an entire Trojan category would not be a valid Defender operation—exclusions are file-, path-, or process-specific, not malware-category-specific. Configuring exclusions would actually undermine protection, whereas the script merely performs a conditional scan. Hence, the claim that it configures Windows Defender to exclude Trojan files is inaccurate.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.