SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your company uses Microsoft Defender for Endpoint. You need to investigate a potential malware outbreak on a specific device. Which feature should you use to get real-time visibility into running processes and network connections?
⚠ Common exam trap
Many candidates confuse the interactive, real-time investigation capability of Live response with the automated, alert-driven workflows of Automated investigation, or they mistake Threat analytics for a tool that provides live device-level data rather than global threat intelligence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Live response
Live response gives security operators a remote shell connection to the device, enabling real-time investigation of running processes, network connections, and other forensic data. This is the correct feature for interactive, real-time visibility into a specific device during an active malware outbreak.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Threat analytics
Why it's wrong here
Threat analytics delivers expert-driven threat intelligence reports, offering insights into active threats, vulnerabilities, and attack campaigns. It helps security teams understand the broader threat landscape and assess their organization's exposure to known threats, but it does not provide a direct mechanism to remotely connect to an endpoint and collect real-time forensic data during an active investigation. Its focus is on strategic awareness and posture, not tactical live data acquisition.
- ✗
Device inventory
Why it's wrong here
Device inventory within Microsoft Defender for Endpoint provides a comprehensive list of all managed devices, detailing their security posture, operating system, and installed Defender components. While it offers a snapshot of device health and configuration, it is a passive reporting feature that does not enable interactive, real-time command execution or dynamic data collection directly from an active endpoint. It serves for asset management and overview, not live forensic analysis.
- ✗
Automated investigation
Why it's wrong here
Automated investigation and remediation capabilities in Microsoft Defender for Endpoint automatically trigger in response to alerts, performing predefined actions to investigate and resolve threats. This process collects forensic artifacts and takes remediation steps without human intervention, but it is not an interactive tool for a security analyst to manually execute custom commands or collect specific, ad-hoc real-time data from an endpoint during an active investigation. It's about automated triage, not interactive live forensics.
- ✓
Live response
Why this is correct
Live response in Microsoft Defender for Endpoint provides security analysts with immediate remote access to an endpoint using a secure shell connection. This capability allows investigators to run commands, collect forensic data such as files, registry keys, and process information in real-time, and take immediate remediation actions directly on the compromised device. It is specifically designed for interactive, on-demand data acquisition and incident response, making it the correct tool for collecting real-time data.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise security solution designed to protect devices from cyber threats using behavioral analysis, machine learning, and automated investigation.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.