nerdexam
MicrosoftMicrosoft

MS-102 · Question #104

MS-102 Question #104: Real Exam Question with Answer & Explanation

Sign in or unlock MS-102 to reveal the answer and full explanation for question #104. The question stem and answer options stay visible for context.

Submitted by certguy· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 tenant that contains a Windows 10 device. The device is onboarded to Microsoft Defender for Endpoint. From Microsoft 365 Defender portal, you perform a security investigation. You need to run a PowerShell script on the device to collect forensic information. Which action should you select on the device page?

Options

  • ACollect investigation package
  • BGo hunt
  • CInitiate Live Response Session
  • DInitiate Automated Investigation

Unlock MS-102 to see the answer

You've previewed enough free MS-102 questions. Unlock MS-102 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Microsoft Defender for Endpoint#Live Response#Security Investigation#Forensics
Full MS-102 PracticeBrowse All MS-102 Questions