SC-200 · Question #153
You are a SOC Analyst of a company XYZ that has implemented Microsoft Defender for Endpoint. You are allocated an incident with alerts related to a doubtful PowerShell command line. You start by…
The correct answer is A. Prefetch Files. When you collect an Investigation Package from a device in Microsoft Defender for Endpoint, it bundles several forensic artifacts including prefetch files, autoruns, installed programs, network connections, processes, scheduled tasks, security event logs, services, Windows SMB…
Question
You are a SOC Analyst of a company XYZ that has implemented Microsoft Defender for Endpoint. You are allocated an incident with alerts related to a doubtful PowerShell command line. You start by going through the incident and apprehend all the related alerts, devices, and evidence. You open the alert page to evaluate the Alert and choose to perform further analysis on the device. You open the Device page and decide that you require remote access to the device to collect more forensics information using a custom .ps1 script. Which type of information is gathered in an Investigation package?
Options
- APrefetch Files
- BNetwork transactions
- CCommand History
- DProcess History
How the community answered
(33 responses)- A94% (31)
- B3% (1)
- D3% (1)
Explanation
When you collect an Investigation Package from a device in Microsoft Defender for Endpoint, it bundles several forensic artifacts including prefetch files, autoruns, installed programs, network connections, processes, scheduled tasks, security event logs, services, Windows SMB sessions, and registry hives. Prefetch files (.pf) are particularly valuable because Windows creates them each time a program runs, recording execution timestamps and file paths-making them critical for establishing what was executed on a compromised machine. 'Command History,' 'Process History,' and 'Network transactions' as labeled in the choices are not discrete components of the collected investigation package.
Topics
Community Discussion
No community discussion yet for this question.