MicrosoftMicrosoft
SC-200 · Question #408
SC-200 Question #408: Real Exam Question with Answer & Explanation
Sign in or unlock SC-200 to reveal the answer and full explanation for question #408. The question stem and answer options stay visible for context.
Submitted by klara.se· Apr 18, 2026
Question
You have a Microsoft 365 E5 subscription that contains a device named Device1. From the Microsoft Defender portal, you discover that an alert was triggered for Device1. From the Device inventory page, you isolate Device1. You need to collect a list of installed programs on Device1. What should you do?
Options
- ACollect an investigation package and download the results from the Action center.
- BInitiate a live response session and run the analyze command.
- CRun an advanced hunting query against the DeviceProcessEvents table.
- DRun an advanced hunting query against the DeviceTvmInfoGathering table.
Unlock SC-200 to see the answer
You've previewed enough free SC-200 questions. Unlock SC-200 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.