Microsoft Security Operations Analyst Associate SC-200 Practice Question
During an investigation you need to obtain volatile and non-volatile artifacts from a Windows 11 device named LON-PC1-such as active processes, registry hives, and recent network connections. Because the user is offline, you cannot establish or maintain an interactive session. In the Microsoft 365 Defender portal, which device action should you choose so that the required artifacts are automatically gathered and uploaded to the device page for later download?
Use the Download file action for C:\Windows\System32
Collect investigation package
Trigger a Microsoft Defender full scan
Initiate a live response session and run ad-hoc commands
The Collect investigation package (also called Collect forensic data) action instructs the Defender for Endpoint sensor to gather a standard set of forensic artifacts-including running processes, network statistics, registry data, and relevant log files-without requiring an interactive session. Once collection finishes, the data is uploaded to the device page where it can be downloaded for up to 30 days. Initiating a live-response session could collect similar data but requires a console connection and manual commands. Triggering a full antivirus scan searches for malware but produces no forensic package, and the Download file action retrieves only one specified file rather than a complete evidence set.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are volatile and non-volatile artifacts in digital investigations?
Open an interactive chat with Bash
How does the 'Collect investigation package' action work in Microsoft 365 Defender?
Open an interactive chat with Bash
What is the difference between 'Collect investigation package' and 'Initiate a live response session'?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .