Collecting a Defender for Endpoint investigation package to get network, process, and login data with least effort

Respond to alerts and incidents in Microsoft Defender for Endpoint
Answer Correct answer: A — The investigation package bundles network, process, and login data in one action, meeting the least-effort requirement.

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2 and contains a macOS device named Device1. You need to investigate a Defender for Endpoint agent alert on Device1. The solution must meet the following requirements: • Identify all the active network connections on Device1. • Identify all the running processes on Device1. • Retrieve the login history of Device1. • Minimize administrative effort. What should you do first from the Microsoft Defender portal?

  1. From Devices, click Collect investigation package for Device1. Correct Answer
  2. From Advanced features in Endpoints, enable Live Response unsigned script execution.
  3. From Devices, initiate a live response session on Device1.
  4. From Advanced features in Endpoints, disable Authenticated telemetry.

Community Votes

A
69%
C
31%

69% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The investigation package aggregates live device state — including network connections, running processes, and login history — in a single download, so it meets all requirements with far less effort than an interactive live response session.

To gather active network connections, running processes, and login history from a macOS device with least administrative effort, collect the Defender for Endpoint investigation package, which bundles all of that data without an interactive session.

Initiating a live response session — it is interactive and more administrative effort; the same information is already captured by the investigation package, which the question's 'minimize administrative effort' criterion favors.

Community Discussion (10 comments)

wheeldj 👍 11 Selected: A
Answer A: The investigation package collected by defender includes all the required information and is considerable less admin effort than running a live response session and collecting this information interactively. https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts?view=o365-worldwide#collect-investigation-package-from-devices
DChilds 👍 5 Selected: A
A is correct. https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts?view=o365-worldwide#collect-investigation-package-from-devices
CDR 👍 2 Selected: C
The correct answer is C. From Devices, initiate a live response session on Devic
sapphire 👍 2 Selected: A
• Minimize administrative effort. A is Correct.
rebecchu0731 👍 1
Asked copilot and answer is live session. While collecting an investigation package can provide a snapshot of the device’s current state, it may not offer the same level of detailed, real-time information and control as a live response session.
smanzana 👍 2
A https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts?view=o365-worldwide#collect-investigation-package-from-devices
Avaris 👍 2 Selected: C
checked chat-gpt and the answer is C Here's why: Initiating a live response session allows you to interact with Device1 in real-time. You can run commands to check active network connections, running processes, and retrieve the login history. Minimize administrative effort: Live response sessions provide direct access and control, which minimizes the need for additional configurations or complex procedures. The other options either involve additional steps that are not immediately necessary (like collecting an investigation package, which can be more comprehensive but less direct for immediate queries) or configurations that don't directly address the investigative tasks at hand. By starting a live response session, you can quickly gather the necessary information directly from Device1, fulfilling the investigation requirements effectively.
laddu001 👍 2
Minimize Administrative Effort: Live response sessions allow you to interact directly with the device, minimizing administrative overhead.
ServerBrain 👍 2 Selected: C
By initiating a live response session, you can achieve your investigation goals while minimizing administrative effort. Remember that live response provides real-time access to the device, allowing you to perform tasks directly on Device
pk69 👍 2 Selected: C
live response session

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The Defender for Endpoint investigation package, collected from the device page, contains the device's current state including active network connections, running processes, and login history. Collecting it is a single action with no interactive session, directly satisfying the 'minimize administrative effort' requirement.

Why the Other Options Are Wrong

Initiating a live response session (C) is interactive and more effort, and the data is already available via the package. Enabling Live Response unsigned script execution (B) or disabling Authenticated telemetry (D) are unrelated advanced configuration changes that do not by themselves produce the required investigative data.

Community Comment Notes

wheeldj (11 likes) and DChilds both cite the collect-investigation-package documentation, noting it includes all required information with less effort than live response. A minority (CDR, Avaris, ServerBrain) prefers C, but the 'minimize administrative effort' wording points to A.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide