ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 258 - SC-200 discussion

Report
Export

You have a Microsoft 365 E5 subscription that contains a device named Device 1. Device 1 is enrolled in Microsoft Defender for End point.

Device1 reports an incident that includes a file named File1 exe as evidence.

You initiate the Collect Investigation Package action and download the ZIP file.

You need to identify the first and last time File1.exe was executed.

What should you review in the investigation package?

A.

Processes

Answers
A.

Processes

B.

Scheduled tasks

Answers
B.

Scheduled tasks

C.

Autoruns

Answers
C.

Autoruns

D.

Security event log

Answers
D.

Security event log

E.

Prefetch files

Answers
E.

Prefetch files

Suggested answer: E
asked 05/10/2024
Kurt Onal
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first