MS-102 Practice Question 3091
Exam: MS-102
Domain: Manage security and threats using Microsoft Defender XDR
Difficulty: medium
You want to collect a forensic investigation package from a compromised Windows workstation for offline malware analysis. What Defender for Endpoint response action performs this?
Answer Options
A
Collect investigation package response action
B
BitLocker remote erase command
C
Format hard drive action
D
Send email report to user
Correct Answer
A: Collect investigation package response action
Explanation
The "Collect investigation package" action compiles a zip archive containing autoruns, event logs, network connections, and execution history from the target machine.