MS-102 Practice Question 3091

Exam: MS-102
Domain: Manage security and threats using Microsoft Defender XDR
Difficulty: medium
You want to collect a forensic investigation package from a compromised Windows workstation for offline malware analysis. What Defender for Endpoint response action performs this?

Answer Options

A
Collect investigation package response action
B
BitLocker remote erase command
C
Format hard drive action
D
Send email report to user

Correct Answer

A: Collect investigation package response action

Explanation

The "Collect investigation package" action compiles a zip archive containing autoruns, event logs, network connections, and execution history from the target machine.