Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Defender XDR. A user reports that their device is behaving erratically, with unexpected pop-ups and high CPU usage. You suspect malware infection. You need to collect forensic data from the device for analysis. What should you do?

⚠ Common exam trap

Watch out — candidates often confuse remediation actions (like running a scan or re-onboarding) with forensic data collection, failing to recognize that live response is the only option that provides interactive, real-time access for gathering evidence without altering the system state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Initiate a live response session on the device from the Microsoft 365 Defender portal.

Initiating a live response session from the Microsoft 365 Defender portal allows you to remotely connect to the device and perform real-time forensic data collection, such as running scripts, capturing memory dumps, and collecting files, without disrupting the device's state. This is the appropriate method for gathering forensic evidence when malware is suspected, as it provides deep, interactive access for analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a custom detection rule in Microsoft Defender for Endpoint to capture the behavior.

    Why it's wrong here

    Custom detection rules in Defender for Endpoint are KQL-based alert rules that asynchronously evaluate telemetry; they can flag suspicious behavior but cannot provide an interactive shell to collect forensic artifacts from a live device. Creating a rule will not immediately capture memory, running processes, or user-owned files, which are essential for triaging a user-reported incident. For on-demand evidence collection, a live response session is the appropriate mechanism.

  • ✗

    Offboard the device and re-onboard it to trigger a fresh investigation.

    Why it's wrong here

    Offboarding and re-onboarding a device disconnects the sensor, stops telemetry ingestion, and then re-establishes it after a new registration; this process forces a fresh device health snapshot but does not grant access to existing forensic data or volatile state. It also introduces a monitoring gap during the offboarded window and can trigger unrelated alerts. It neither interactively collects artifacts nor preserves evidence required for a user-reported investigation.

  • ✓

    Initiate a live response session on the device from the Microsoft 365 Defender portal.

    Why this is correct

    Initiating a live response session from the Microsoft 365 Defender portal opens a secure, interactive remote shell to the device, allowing an analyst to execute built-in and custom commands to collect registry keys, running processes, network connections, and specific files into an evidence package. It is the correct choice for immediate forensic triage because it provides direct, time-sensitive access to volatile artifacts without relying on automated detection. The session is fully audited and can be used to run live response scripts or collect suspicious binaries for further analysis.

  • ✗

    Run a full antivirus scan using Microsoft Defender Antivirus.

    Why it's wrong here

    Running a full Microsoft Defender Antivirus scan performs signature-based and heuristic malware detection and can remediate simple threats, but it does not collect forensic data for analysis or give the analyst interactive visibility into the user-reported incident. The scan is a reactive remediation step that may alter or quarantine files, potentially destroying volatile evidence. Forensic collection for investigation requires a tool like live response that preserves artifact state rather than scanning for known badness.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.