certslothcertsloth
SC-200/Topic 04

Microsoft / Associate

Endpoint Controls and Investigation

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Contain the device while preserving the story.

Must remember

Onboard supported devices and verify sensor health, connectivity and data availability. Device groups scope access and automation behavior. Advanced features, rules and indicators change endpoint behavior; confirm licensing, platform support and conflicts with other management channels before assuming one setting applies everywhere.

Attack surface reduction (ASR) rules prevent risky behaviors. Audit mode observes impact; block mode enforces; exclusions should be narrow and justified. An ASR policy is a preventive control, while an investigation timeline is evidence about what happened. Use staged rollout and measured impact for legitimate applications.

Investigate the device timeline, process tree, command line, network activity, file hashes, user context and related alerts. Parent/child processes and timing can distinguish an ordinary administrative tool from suspicious use. A hash match is one indicator, not a complete explanation of execution or intent.

Response options include supported isolation, antivirus scans, investigation packages and live response. Isolation changes connectivity; collecting a package preserves useful artifacts. Live response is powerful and must use authorized commands and role permissions. Capture enough evidence before destructive remediation, while prioritizing urgent containment where necessary.

Follow automated investigations through pending actions, approvals and completion. Validate that persistence and related identities are addressed before reconnecting a device. Closing the alert is workflow bookkeeping, not proof of eradication. Document scope, evidence, action times and reasons so the incident can be reconstructed.

Choose under exam pressure

Requirement Choice and reason
Understand suspicious execution sequence Device timeline and process/entity evidence.
Assess an ASR rule before broad enforcement Audit/staged rollout with measured impact.
Limit a compromised device’s communication Authorized supported isolation, with evidence and recovery planning.

Traps

  • A closed alert does not certify a clean endpoint.
  • Blocking a file alone may leave the compromised identity or persistence mechanism active.

Active recall

1. Why use device groups?

To scope device access and automation behavior.

2. Audit versus block mode?

Observe policy matches versus enforce prevention.

3. Why inspect parent processes?

They help explain how and why a process started.

4. Investigation package versus live response?

Collected diagnostic artifacts versus an interactive authorized response capability.

5. What precedes reconnection?

Validation of remediation, persistence removal and affected identity recovery.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.