nerdexam
Microsoft

SC-200 · Question #425

You have a Microsoft 365 E5 subscription that contains a device named Device1. From the Microsoft Defender portal, you discover that an alert was triggered for Device1. From the Device inventory…

The correct answer is B. Collect an investigation package and download the results from the Action center. When a device is isolated in Microsoft Defender for Endpoint, you can still collect an investigation package from it remotely. This package is a zip file that contains forensic artifacts including the list of installed programs, running processes, network connections, event…

Submitted by weili_xi· Apr 18, 2026

Question

You have a Microsoft 365 E5 subscription that contains a device named Device1. From the Microsoft Defender portal, you discover that an alert was triggered for Device1. From the Device inventory page, you isolate Device1. You need to collect a list of installed programs on Device1. What should you do?

Options

  • AInitiate an automated investigation and view the results in the Action center.
  • BCollect an investigation package and download the results from the Action center.
  • CRun an advanced hunting query against the DeviceTvmInfoGathering table.
  • DRun an advanced hunting query against the DeviceProcessEvents table.

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    74% (14)
  • C
    16% (3)
  • D
    5% (1)

Explanation

When a device is isolated in Microsoft Defender for Endpoint, you can still collect an investigation package from it remotely. This package is a zip file that contains forensic artifacts including the list of installed programs, running processes, network connections, event logs, and more. After the collection completes, the package becomes available to download from the Action center. Option A (automated investigation) does not specifically target installed software inventory. Option C (DeviceTvmInfoGathering) and D (DeviceProcessEvents) are Advanced Hunting tables - DeviceProcessEvents logs process execution events, not installed programs, and running queries against an isolated device does not trigger remote collection.

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice