Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

Refer to the exhibit.

$alert = Get-MpThreatDetection | Where-Object {$_.ThreatName -like "*Trojan*"}
if ($alert) {
    Start-MpScan -ScanType QuickScan
}

You are reviewing a PowerShell script used for automated response on a Windows 10 device managed by Microsoft Defender for Endpoint. What is the intended outcome of this script?

⚠ Common exam trap

A common mix-up: candidates assume the script performs remediation (option A) or updates signatures (option B) because those are common steps in response workflows, but the script only triggers a scan based on detection, not removal or update actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It triggers a quick scan if any Trojan detection exists.

The script checks for Trojan detections using Get-MpThreat with a threat category filter for Trojans. If any Trojan is found, it triggers Start-MpScan -ScanType QuickScan to perform a quick scan. This matches option C exactly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It removes all Trojan threats from the device.

    Why it's wrong here

    The script is only performing a detection and scan operation; it never calls a remediation cmdlet such as Remove-MpThreat or invokes an action like ThreatIDDefaultAction. Trojan removal would require either an explicit remediation step or the automatic remediation pipeline, neither of which is present in the described script. Therefore, stating that it removes all Trojan threats overstates the script's actual behavior.

  • ✗

    It updates the antimalware signatures and then performs a scan.

    Why it's wrong here

    No Update-MpSignature, Update-MpAntimalware, or similar definition-update cmdlet is invoked anywhere in the described flow. The script conditions its scan on existing Trojan detections, but it does not refresh the antimalware signatures before doing so. Relying on stale definitions could produce incomplete results, but that is not the behavior being described here—only the conditional quick scan occurs.

  • ✓

    It triggers a quick scan if any Trojan detection exists.

    Why this is correct

    The script includes a conditional statement that evaluates whether any Trojan threat detection is present, likely using Get-MpThreatDetection or Get-MpThreat with a filter for the Trojan threat category. When that condition is true, it executes Start-MpScan with the QuickScan parameter. Because the decision to run the quick scan depends directly on the presence of Trojan detections, the correct characterization is that it triggers a quick scan if any Trojan detection exists.

  • ✗

    It configures Windows Defender to exclude Trojan files.

    Why it's wrong here

    There is no use of Add-MpPreference to create path, extension, or process exclusions, and excluding an entire Trojan category would not be a valid Defender operation—exclusions are file-, path-, or process-specific, not malware-category-specific. Configuring exclusions would actually undermine protection, whereas the script merely performs a conditional scan. Hence, the claim that it configures Windows Defender to exclude Trojan files is inaccurate.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.