nerdexam
Microsoft

SC-200 · Question #426

You have a Microsoft 365 E5 subscription that contains a device named Device1. From the Microsoft Defender portal, you discover that an alert was triggered for Device1. From the Device inventory…

The correct answer is D. Run an advanced hunting query against the DeviceTvmSoftwareInventory table. The DeviceTvmSoftwareInventory table in Microsoft Defender XDR advanced hunting contains a comprehensive inventory of software installed on onboarded devices, including application name, version, vendor, and installation path. TVM stands for Threat and Vulnerability Management…

Submitted by hassan_iq· Apr 18, 2026

Question

You have a Microsoft 365 E5 subscription that contains a device named Device1. From the Microsoft Defender portal, you discover that an alert was triggered for Device1. From the Device inventory page, you isolate Device1. You need to collect a list of installed programs on Device1. What should you do?

Options

  • ARun an advanced hunting query against the DeviceProcessEvents table.
  • BInitiate an automated investigation and view the results in the Action center.
  • CRun an advanced hunting query against the DeviceTvmInfoGathering table.
  • DRun an advanced hunting query against the DeviceTvmSoftwareInventory table.

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    16% (4)
  • C
    4% (1)
  • D
    76% (19)

Explanation

The DeviceTvmSoftwareInventory table in Microsoft Defender XDR advanced hunting contains a comprehensive inventory of software installed on onboarded devices, including application name, version, vendor, and installation path. TVM stands for Threat and Vulnerability Management. Even when a device is isolated, this data is already collected and available in the Defender backend, so querying this table is the correct approach. DeviceProcessEvents (A) tracks process execution events, not installed software. DeviceTvmInfoGathering (C) stores additional device configuration and capability data, not software inventory. Running an automated investigation (B) would not specifically enumerate installed programs.

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice