Microsoft Security Operations Analyst Associate SC-200 Practice Question
While triaging a malware alert in Microsoft Defender for Endpoint, you open the device timeline for the affected Windows 11 workstation. You must quickly locate every event where a registry value was changed on the device during the last two weeks so you can determine whether the malware modified Run-key startup entries. Which action should you take in the device timeline pane to accomplish this task with the least amount of effort?
Scroll through the timeline manually and mark every registry event with the Add to evidence command.
Export the timeline to CSV and search the file for registry events by using a spreadsheet filter.
Start a Live Response session and run a registry command to enumerate Run-key entries.
Apply an Advanced filter that specifies Action type equals Registry value set and limits the date range to the last 14 days.
In the device timeline, the fastest way to isolate only registry change events is to use the built-in Advanced filters feature. Selecting Action type equals Registry value set (or Registry value deleted/created) and narrowing the Date range to the last 14 days immediately hides all other event categories such as file, network, or process events. Manually scrolling, exporting raw data, or running a Live Response session are unnecessary and more time-consuming for the stated goal.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Advanced filter in Microsoft Defender for Endpoint?
Open an interactive chat with Bash
How do malware attacks typically use Run-key registry entries?
Open an interactive chat with Bash
Why is exporting the timeline to CSV not recommended for registry investigations?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .