FEFreeExamDumps.in

Microsoft Security Operations Analyst

Topic 7

Question 257

SC-200 voucher + Udemy course (lifetime access) = ₹3,500 for Indian ID card holders.

Details →

You have 1,000 on-premises Windows 11 Pro devices that are onboarded to Microsoft Defender for Endpoint. You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You identify that an attacker performed the following actions on a device: • Modified the file system path of a registry-based antivirus exclusion • Downloaded a malicious file to the file system path You initiate a live response session on the device. You need to remove the malicious file. Which command should you run?

  • Acollect
  • Bgetfile
  • Cundo
  • Dremediate