SC-200 Practice Question 3758

Exam: SC-200
Domain: Respond to security incidents
Difficulty: medium
You need to collect an offline forensic bundle from a Windows 11 laptop containing event logs, autorun configurations, network connections, and memory execution state. Which Defender for Endpoint action performs this?

Answer Options

A
Collect investigation package
B
Run Antivirus scan
C
Isolate device
D
Initiate automated investigation

Correct Answer

A: Collect investigation package

Explanation

The "Collect investigation package" device action downloads a structured .zip archive containing comprehensive forensic telemetry directly from the machine.