SC-200 Practice Question 3758
Exam: SC-200
Domain: Respond to security incidents
Difficulty: medium
You need to collect an offline forensic bundle from a Windows 11 laptop containing event logs, autorun configurations, network connections, and memory execution state. Which Defender for Endpoint action performs this?
Answer Options
A
Collect investigation package
B
Run Antivirus scan
C
Isolate device
D
Initiate automated investigation
Correct Answer
A: Collect investigation package
Explanation
The "Collect investigation package" device action downloads a structured .zip archive containing comprehensive forensic telemetry directly from the machine.