Microsoft Security Operations Analyst SC-200 Question # 25 Topic 3 Discussion

Microsoft Security Operations Analyst SC-200 Question # 25 Topic 3 Discussion

SC-200 Exam Topic 3 Question 25 Discussion:
Question #: 25
Topic #: 3

You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR and contains a Windows device named Device1.

You investigate Device1 for malicious activity and discover a suspicious file named File1.exe. You collect an investigation package from Device1.

You need to review the following forensic data points:

. Is an attacker currently accessing Device1 remotely?

. When was File1.exe first executed?

Which folder in the investigation package should you review for each data point? To answer, select the appropriate options in the answer area.

SC-200 Question 25


Get Premium SC-200 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.