nerdexam
Microsoft

SC-200 · Question #291

You have a Microsoft 365 E5 subscription that contains a device named Device1. Device1 is enrolled in Microsoft Defender for Endpoint. Device1 reports an incident that includes a file named…

The correct answer is E. Prefetch files. To identify the first and last time that File1.exe was executed on Device1, you should review the Prefetch files in the investigation package. Prefetch files in Windows are designed to speed up the application launch process and contain information about how often and when a…

Submitted by brentm· Apr 18, 2026

Question

You have a Microsoft 365 E5 subscription that contains a device named Device1. Device1 is enrolled in Microsoft Defender for Endpoint. Device1 reports an incident that includes a file named File1.exe as evidence. You initiate the Collect Investigation Package action and download the ZIP file. You need to identify the first and last time File1.exe was executed. What should you review in the investigation package?

Options

  • AProcesses
  • BAutoruns
  • CSecurity event log
  • DScheduled tasks
  • EPrefetch files

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    5% (2)
  • C
    2% (1)
  • D
    7% (3)
  • E
    84% (37)

Explanation

To identify the first and last time that File1.exe was executed on Device1, you should review the Prefetch files in the investigation package. Prefetch files in Windows are designed to speed up the application launch process and contain information about how often and when a particular application is run. This data can be used to determine the execution history of File1.exe. https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts#collect- investigation-package-from-devices

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice