SC-200 · Question #249
You have a Microsoft 365 E5 subscription that contains 100 Linux devices. The devices are onboarded to Microsoft Defender 365. You need to initiate the collection of investigation packages from the…
The correct answer is C. Collect investigation package. The 'Collect investigation package' response action in Microsoft 365 Defender gathers a ZIP archive of forensic artifacts from the device - including running processes, active network connections, auto-start entries, event logs, and more - for offline analysis. This action is…
Question
You have a Microsoft 365 E5 subscription that contains 100 Linux devices. The devices are onboarded to Microsoft Defender 365. You need to initiate the collection of investigation packages from the devices by using the Microsoft 365 Defender portal. Which response action should you use?
Options
- ARun antivirus scan
- BInitiate Automated Investigation
- CCollect investigation package
- DInitiate Live Response Session
How the community answered
(44 responses)- A2% (1)
- B5% (2)
- C93% (41)
Explanation
The 'Collect investigation package' response action in Microsoft 365 Defender gathers a ZIP archive of forensic artifacts from the device - including running processes, active network connections, auto-start entries, event logs, and more - for offline analysis. This action is explicitly supported on Linux devices onboarded to Defender for Endpoint. 'Run antivirus scan' (A) triggers a scan but collects no package. 'Initiate Automated Investigation' (B) launches an AI-driven investigation but is not a direct package collection. 'Initiate Live Response Session' (D) opens an interactive shell for manual data collection, but the question asks about initiating package collection, which is the purpose-built action C.
Topics
Community Discussion
No community discussion yet for this question.