SC-200 · Question #154
You are a SOC Analyst of a company XYZ that has implemented Microsoft Defender for Endpoint. You are allocated an incident with alerts related to a doubtful PowerShell command line. You start by…
The correct answer is B. Isolate device. You can't issue either reboot, reinstall or reformat action. You can perform isolation devices. Depending on the severity of the attack and the sensitivity of the device, you might want to isolate the device from the network. This action can help prevent the attacker from…
Question
You are a SOC Analyst of a company XYZ that has implemented Microsoft Defender for Endpoint. You are allocated an incident with alerts related to a doubtful PowerShell command line. You start by going through the incident and apprehend all the related alerts, devices, and evidence. You open the alert page to evaluate the Alert and choose to perform further analysis on the device. You open the Device page and decide that you require remote access to the device to collect more forensics information using a custom .ps1 script. Which one of the below is a Device action?
Options
- AReformat device
- BIsolate device
- CReboot
- DReinstall
How the community answered
(21 responses)- B90% (19)
- C5% (1)
- D5% (1)
Explanation
You can't issue either reboot, reinstall or reformat action. You can perform isolation devices. Depending on the severity of the attack and the sensitivity of the device, you might want to isolate the device from the network. This action can help prevent the attacker from controlling the compromised device and performing further activities such as data exfiltration and lateral https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/respond-machine- alerts?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.