SC-200 · Question #451
You have a Microsoft 365 subscription. You have the devices shown in the following table. All the devices are onboarded to Microsoft Defender for Endpoint. You are investigating a potential malware…
The correct answer is D. Initiate a live response session. To investigate malware on a device with Defender for Endpoint, use the portal's device timeline for events, leverage Live Response to get deep system/log access (like Event Viewer/Process Monitor), run the Client Analyzer (MDECA) for rich logs, and then analyze those logs…
Question
You have a Microsoft 365 subscription. You have the devices shown in the following table. All the devices are onboarded to Microsoft Defender for Endpoint. You are investigating a potential malware exploit on the devices. You need to review the system log of each device. The solution must minimize disruptions to the devices. What should you do for each device first in the Microsoft Defender portal?
Options
- AIsolate the device.
- BCollect an investigation package.
- CInitiate an automated investigation.
- DInitiate a live response session.
How the community answered
(27 responses)- A4% (1)
- B7% (2)
- C19% (5)
- D70% (19)
Explanation
To investigate malware on a device with Defender for Endpoint, use the portal's device timeline for events, leverage Live Response to get deep system/log access (like Event Viewer/Process Monitor), run the Client Analyzer (MDECA) for rich logs, and then analyze those logs (PowerShell, WFP, AV) for malicious activity, correlating with portal alerts for the full attack story. 1. Start in the Microsoft Defender Portal (security.microsoft.com) Locate the Device: Go to the "Devices" list and find the affected machine. Review Device Timeline: Check the Timeline tab for a chronological view of events (process creations, network connections, file changes) and alerts. Check Incidents/Alerts: Look at the Incidents & Alerts tab for related security events that Defender has already flagged. *-> 2. Initiate Live Response for Deep Dive Live Response: Select the device and initiate a Live Response session to get a remote shell (PowerShell or Command Prompt). MDE Client Analyzer (MDECA): Within Live Response, upload and run the MDELiveAnalyzer.ps1 script (from the MDE Client Analyzer tool) to collect comprehensive sensor, AV, network (WFP), and process logs. Collect Logs: Use Putfile and GetFile commands to pull the MDEClientAnalyzerResult.zip file to your local machine for analysis. 3. Analyze Collected Logs (on your analyst machine) https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-collect-support-log Exam Questions, Study Guides, Practice Tests. Lead the way to help you pass any IT Certification exams, 100% Pass Guaranteed or Full Refund. Especially Cisco, Microsoft, CompTIA, Citrix, EMC, HP, Oracle, VMware, Juniper, Check Point, LPI, Nortel, EXIN and so on. Our Slogan: First Test, First Pass. Help you to pass any IT Certification exams at the first try. You can reach us at any of the email addresses listed below. Any problems about IT certification or our products, you could rely upon us, we will give you satisfactory answers in 24 hours.
Community Discussion
No community discussion yet for this question.