SC-200 Respond to security incidents Practice Question
Your organization has Microsoft Defender for Endpoint deployed. A security analyst receives an alert about a suspicious PowerShell command executed on a device. The analyst needs to investigate the process tree. Which feature should the analyst use?
⚠ Common exam trap
It's easy for candidates to confuse Live response (a real-time interactive shell) with the Timeline feature (a historical, pre-built process tree), leading them to select Live response because they think it can be used to manually trace processes, but it lacks the automated, visual process tree view needed for efficient investigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Timeline (process timeline)
The Timeline (process timeline) feature in Microsoft Defender for Endpoint allows analysts to view the full process tree, including parent-child relationships, command lines, and timestamps for events like PowerShell execution. This is the correct tool for investigating how a suspicious command was launched and what processes preceded it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Device isolation
Why it's wrong here
Device isolation is a containment action in Microsoft Defender for Endpoint that disconnects a compromised machine from the network while maintaining communication with the Defender service. This action limits lateral movement and stops the spread of malware, but it does not provide any visibility into hidden processes or the sequence of events on the device. The process timeline is specifically designed to present the process tree and event history, so isolation is not the correct feature for this investigation need.
- ✗
Live response
Why it's wrong here
Live response is an interactive remote shell that allows an analyst to run commands, execute scripts, and collect forensic artifacts on an endpoint in real time. While this can be used to inspect processes manually, it does not generate a visual process tree or an aggregated timeline of events. The question asks for a feature that shows the process tree and events, which is the timeline, not live response.
- ✓
Timeline (process timeline)
Why this is correct
The device timeline, also known as the process timeline, is the correct answer because it provides a chronological view of events and a visual representation of the process tree, including parent-child relationships. This allows an analyst to trace an attack chain from initial access to execution, observing how each process was spawned and what actions it performed. It is a core DFIR tool in Microsoft Defender for Endpoint for investigating a single device's historical activity.
- ✗
Advanced hunting
Why it's wrong here
Advanced hunting is a query-based tool that uses Kusto Query Language (KQL) to search across the organization's data for specific indicators and detect sophisticated threats. It returns tabular results of events rather than a visual process tree, and while you can reconstruct process ancestry with queries, it does not present a built-in timeline. For a quick, graphical view of a process tree on a specific machine, the timeline is the appropriate feature, not advanced hunting.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.