Microsoft Security Operations Analyst Associate SC-200 Practice Question
You are investigating an incident in Microsoft Defender for Endpoint. On the Incident page you pivot to the Device timeline of the affected Windows 11 laptop. The SOC lead asks you to collect the standard investigation package from the device so that you can examine recent persistence mechanisms offline. From the Device timeline you initiate a live response session and must now run a single command that:
gathers the preset collection of triage artefacts (registry hives, running processes, network connections, scheduled tasks, etc.)
automatically uploads the resulting ZIP file to the portal for later download Which live response command should you run?
The built-in collect command in a Microsoft Defender for Endpoint live response session gathers the predefined investigation package that includes registry hives, autoruns information, running processes, network connections, scheduled tasks, and other artefacts. After execution it compresses the data into a ZIP file and securely uploads it to the Defender portal where analysts can download it.
Other options either gather only a single file (getfile), capture a full memory dump (collectmemory), or download data from the device (download) but none of them create the complete investigation package required for standard triage.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of the live response `collect` command in Microsoft Defender for Endpoint?
Open an interactive chat with Bash
What artefacts are included in the investigation package collected by the `collect` command?
Open an interactive chat with Bash
How does the `collect` command differ from `getfile` in Microsoft Defender for Endpoint?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .