Collecting a Defender for Endpoint investigation package via CLI live response only on macOS and Linux devices

Respond to alerts and incidents in Microsoft Defender for Endpoint
Answer Correct answer: C — The CLI 'collect' live-response command is supported on macOS and Linux but not Windows, so only Device3 and Device4 qualify.

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint and contains the devices shown in the following table. You initiate a live response session on each device. You need to collect a Defender for Endpoint investigation package from each device. On which devices can you collect the package by running advanced live response commands from the command-line interface (CLI)? - image

  1. Device1 and Device2 only
  2. Device1, Device2, and Device3 only
  3. Device3 and Device4 only Correct Answer
  4. Device1, Device2, Device3, and Device4

Community Votes

C
82%
D
18%

82% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The Defender for Endpoint live-response advanced command 'collect' (forensics package) is marked N for Windows, Y for macOS, and Y for Linux, which determines which platforms can run it from the CLI.

You start advanced live response sessions and must collect the investigation package by using CLI advanced commands; the Collect command is supported on macOS and Linux but not on Windows, so only the macOS/Linux devices in the table qualify.

Assuming Windows devices support the CLI Collect command — the advanced command table explicitly shows Windows as Not supported, so only the macOS and Linux devices can collect the package this way.

Community Discussion (7 comments)

Onimole 👍 2 Selected: C
Answer is device 3 and 4 collect ---> Collects forensics package from device. N (windows ) Y (linux) Y (mac) https://learn.microsoft.com/en-us/defender-endpoint/live-response
Itsmebigal 👍 2 Selected: C
Command Description Windows and Windows Server macOS Linux collect Collects forensics package from device. N Y Y https://learn.microsoft.com/en-us/defender-endpoint/live-response
1375514 👍 2 Selected: C
https://learn.microsoft.com/en-us/defender-endpoint/live-response The Advanced Commands table states that Collect is only available on MacOS and Linux.
cypkir 👍 2 Selected: D
All of them! Source: https://learn.microsoft.com/en-us/defender-endpoint/live-response
Sophonk 👍 1 Selected: D
New GPT: Windows: Versions 10 and 11 (specifically, Version 1909 or later, and some earlier versions with specific updates) macOS: Intel-based and ARM-based devices running version 101.43.84 or later Linux: Supported server distributions and kernel versions Windows Server: 2012 R2, 2016, and 2019 (with specific updates)
sapphire 👍 3 Selected: C
Correct answer is C. You can collect from Linux and MacOS. Source: https://learn.microsoft.com/en-us/defender-endpoint/live-response
chirva 👍 1
GPT: Windows Devices: Yes, you can collect a Defender for Endpoint investigation package from Windows devices using advanced live response commands. Linux Devices: No, as of the latest updates, collecting investigation packages using advanced live response commands is not supported on Linux devices. MacOS Devices: Yes, you can collect a Defender for Endpoint investigation package from MacOS devices using advanced live response commands. Therefore, you can collect the investigation package by running advanced live response commands from the CLI on Windows and MacOS devices, but not on Linux devices.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The Defender for Endpoint live-response advanced commands table lists the 'collect' command (which collects a forensics/investigation package from a device) as supported on macOS and Linux but not on Windows. In the device table, only Device3 and Device4 run macOS/Linux, so they are the only devices from which you can collect the package via advanced CLI commands.

Why the Other Options Are Wrong

Including Device1 and Device2 (Windows) is incorrect because the 'collect' advanced command is not available on Windows through the CLI. Options that add any Windows device (A, B, D) therefore fail the platform-support constraint.

Community Comment Notes

sapphire, Onimole, Itsmebigal, and 1375514 all cite https://learn.microsoft.com/en-us/defender-endpoint/live-response, confirming the Collect advanced command is Y for macOS and Linux and N for Windows. The community strongly favors C (82 votes).

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide