nerdexam
Microsoft

SC-200 · Question #156

What information is shared by a deep file analysis?

The correct answer is A. Registry Modifications. Deep file analysis (also called sandbox detonation) in Microsoft Defender for Endpoint submits a suspicious file to a sandboxed environment for behavioral analysis. The results surface dynamic behaviors observed during execution, including registry modifications (A) - such as…

Submitted by takeshi77· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Endpoint

Question

What information is shared by a deep file analysis?

Options

  • ARegistry Modifications
  • BCode change history
  • CCommand history
  • DProcess history

How the community answered

(55 responses)
  • A
    89% (49)
  • B
    4% (2)
  • C
    5% (3)
  • D
    2% (1)

Explanation

Deep file analysis (also called sandbox detonation) in Microsoft Defender for Endpoint submits a suspicious file to a sandboxed environment for behavioral analysis. The results surface dynamic behaviors observed during execution, including registry modifications (A) - such as keys created, modified, or deleted - as well as process creation, file system activity, and network connections. 'Code change history' is not a behavioral artifact. 'Command history' and 'Process history' are investigative artifacts collected from live devices (e.g., in investigation packages or Live Response), not outputs of static/dynamic file detonation analysis.

Topics

#Deep file analysis#Malware analysis#Registry modifications#Behavioral analysis

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice