nerdexam
Microsoft

SC-200 · Question #153

You are a SOC Analyst of a company XYZ that has implemented Microsoft Defender for Endpoint. You are allocated an incident with alerts related to a doubtful PowerShell command line. You start by…

The correct answer is A. Prefetch Files. When you collect an Investigation Package from a device in Microsoft Defender for Endpoint, it bundles several forensic artifacts including prefetch files, autoruns, installed programs, network connections, processes, scheduled tasks, security event logs, services, Windows SMB…

Submitted by wei.xz· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Endpoint

Question

You are a SOC Analyst of a company XYZ that has implemented Microsoft Defender for Endpoint. You are allocated an incident with alerts related to a doubtful PowerShell command line. You start by going through the incident and apprehend all the related alerts, devices, and evidence. You open the alert page to evaluate the Alert and choose to perform further analysis on the device. You open the Device page and decide that you require remote access to the device to collect more forensics information using a custom .ps1 script. Which type of information is gathered in an Investigation package?

Options

  • APrefetch Files
  • BNetwork transactions
  • CCommand History
  • DProcess History

How the community answered

(33 responses)
  • A
    94% (31)
  • B
    3% (1)
  • D
    3% (1)

Explanation

When you collect an Investigation Package from a device in Microsoft Defender for Endpoint, it bundles several forensic artifacts including prefetch files, autoruns, installed programs, network connections, processes, scheduled tasks, security event logs, services, Windows SMB sessions, and registry hives. Prefetch files (.pf) are particularly valuable because Windows creates them each time a program runs, recording execution timestamps and file paths-making them critical for establishing what was executed on a compromised machine. 'Command History,' 'Process History,' and 'Network transactions' as labeled in the choices are not discrete components of the collected investigation package.

Topics

#Microsoft Defender for Endpoint#Forensic investigation#Investigation package#Live Response

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice