Respond to alerts and incidents in Microsoft Defender for Endpoint
4 practice questions under this official exam objective (SC-200) — each with the community-verified answer, a full option-by-option explanation and instant feedback.
Collecting a Defender for Endpoint investigation package to get network, process, and login data with least effort
To gather active network connections, running processes, and login history from a macOS device with least administrative effort, collect the Defender
Reviewing Prefetch files in the investigation package to find first and last execution times of an executable
After collecting a Defender for Endpoint investigation package, you need the first and last execution time of File1.exe; the Prefetch files in the pac
Collecting a Defender for Endpoint investigation package via CLI live response only on macOS and Linux devices
You start advanced live response sessions and must collect the investigation package by using CLI advanced commands; the Collect command is supported
Uploading a signed PowerShell script to the live response library before running it
To run a digitally signed PowerShell script in a Defender for Endpoint live response session, you must first upload the script to the live response li