MicrosoftMicrosoft
MS-102 · Question #104
MS-102 Question #104: Real Exam Question with Answer & Explanation
Sign in or unlock MS-102 to reveal the answer and full explanation for question #104. The question stem and answer options stay visible for context.
Submitted by certguy· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR
Question
You have a Microsoft 365 tenant that contains a Windows 10 device. The device is onboarded to Microsoft Defender for Endpoint. From Microsoft 365 Defender portal, you perform a security investigation. You need to run a PowerShell script on the device to collect forensic information. Which action should you select on the device page?
Options
- ACollect investigation package
- BGo hunt
- CInitiate Live Response Session
- DInitiate Automated Investigation
Unlock MS-102 to see the answer
You've previewed enough free MS-102 questions. Unlock MS-102 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Microsoft Defender for Endpoint#Live Response#Security Investigation#Forensics