Collecting a Defender for Endpoint investigation package to get network, process, and login data with least effort
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2 and contains a macOS device named Device1. You need to investigate a Defender for Endpoint agent alert on Device1. The solution must meet the following requirements: • Identify all the active network connections on Device1. • Identify all the running processes on Device1. • Retrieve the login history of Device1. • Minimize administrative effort. What should you do first from the Microsoft Defender portal?
Community Votes
69% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The investigation package aggregates live device state — including network connections, running processes, and login history — in a single download, so it meets all requirements with far less effort than an interactive live response session.
To gather active network connections, running processes, and login history from a macOS device with least administrative effort, collect the Defender for Endpoint investigation package, which bundles all of that data without an interactive session.
Initiating a live response session — it is interactive and more administrative effort; the same information is already captured by the investigation package, which the question's 'minimize administrative effort' criterion favors.
Community Discussion (10 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The Defender for Endpoint investigation package, collected from the device page, contains the device's current state including active network connections, running processes, and login history. Collecting it is a single action with no interactive session, directly satisfying the 'minimize administrative effort' requirement.Why the Other Options Are Wrong
Initiating a live response session (C) is interactive and more effort, and the data is already available via the package. Enabling Live Response unsigned script execution (B) or disabling Authenticated telemetry (D) are unrelated advanced configuration changes that do not by themselves produce the required investigative data.Community Comment Notes
wheeldj (11 likes) and DChilds both cite the collect-investigation-package documentation, noting it includes all required information with less effort than live response. A minority (CDR, Avaris, ServerBrain) prefers C, but the 'minimize administrative effort' wording points to A.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →