What's changed: Created SC-200 Chapter 4 (Domain 2: Defender XDR incident investigation/remediation (coverage of Defender for Office 365/Purview/Defender for Cloud workload protections/Defender for Cloud Apps/Entra ID Protection/Defender for Identity/Sentinel); complex attacks (multistage/multi-domain/lateral movement)/attack story (incident graph)/embedded Microsoft Security Copilot (agentic AI)/case management; Defender for Endpoint response (device timeline/live response/investigation package collection/evidence-entity investigation/automatic attack disruption); M365 investigation (Purview Audit/Purview eDiscovery Content search/Microsoft Graph activity logs)).
4.3Device response in Defender for Endpoint
Understand investigating device timelines, performing device actions (live response, collecting investigation packages), evidence/entity investigation, and responding to incidents identified by automatic attack disruption in Microsoft Defender for Endpoint.
On a suspected device, trace what happened chronologically and, if needed, operate remotely to contain it. Defender for Endpoint provides these as an EDR.
4.3.1Device timeline and evidence investigation
The device timeline shows events on a device (processes, files, network, registry) chronologically, reconstructing the attack. Investigate an incident’s evidence and entities (files/processes/IPs/users) to judge maliciousness. Analysts identify scope from the timeline and decide whether remediation is needed.
4.3.2Device actions and attack disruption
For remote response, use live response (shell into the device to fetch files, stop processes, run scripts), collect an investigation package (bulk forensic data), isolate the device, block files, etc. If automatic attack disruption (Chapter 1) has already isolated/contained the device, analysts confirm the result, investigate root cause, and release isolation after verifying safety.
Cues: "trace events on a device chronologically" = device timeline. "remotely shell in to fetch files/stop processes/run scripts" = live response. "bulk-collect forensic data" = collect investigation package. "in-progress attack already auto-contained" = confirm and act on automatic attack disruption result.
Watch the mix-ups: (1) Live response (interactive remote operation) vs collecting an investigation package (bulk forensic capture). (2) Device timeline (chronological events) vs Advanced Hunting (cross-cutting queries). (3) Release disruption-driven isolation only after verifying safety.
4.3.3Section summary
- Trace chronological events via device timeline; investigate evidence/entities to identify scope
- Respond with live response (remote shell), collecting an investigation package (bulk forensics), and isolation
- Confirm automatic attack disruption containment; release isolation after root-cause investigation
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. You want to remotely shell into a suspected device to fetch files, stop processes, and run scripts. Which is best?
Q2. You want to trace process/file/network events on a device chronologically to reconstruct the attack. Which is best?
Q3. For forensic analysis, you want to bulk-collect related information from a device. Which is best?
Q4. Which correctly distinguishes live response from collecting an investigation package?
Q5. Automatic attack disruption has already isolated the device. What is the analyst’s best action?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

