ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 266 - SC-200 discussion

Report
Export

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 1 and contains a macOS device named Device1.

You need to investigate a Defender for Endpoint agent alert on Device1. The solution must meet the following requirements:

* Identify all the active network connections on Device1.

* Identify all the running processes on Device1.

* Retrieve the login history of Device1.

* Minimize administrative effort.

What should you do first from the Microsoft Defender portal?

A.

From Advanced features in Endpoints, disable Authenticated telemetry.

Answers
A.

From Advanced features in Endpoints, disable Authenticated telemetry.

B.

From Advanced features in Endpoints, enable Live Response unsigned script execution.

Answers
B.

From Advanced features in Endpoints, enable Live Response unsigned script execution.

C.

From Devices, click Collect investigation package for Device 1.

Answers
C.

From Devices, click Collect investigation package for Device 1.

D.

From Devices, initiate a live response session on Device1.

Answers
D.

From Devices, initiate a live response session on Device1.

Suggested answer: C
asked 05/10/2024
Mark Oh
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first