exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 6 question 8 discussion

Actual exam question from Microsoft's SC-200
Question #: 8
Topic #: 6
[All SC-200 Questions]

HOTSPOT
-

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint and contains a Windows device named Device1.

You need to investigate a suspicious executable file detected on Device1. The solution must meet the following requirements:

• Identify the image file path of the file.
• Identify when the file was first detected on Device1.

What should you review from the timeline of the detection event? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
laddu001
Highly Voted 11 months, 1 week ago
To identify the image file path: Review the Event entities graph: This graph will display the relationships and interactions involving the file, including the full image file path. By examining the graph, you can trace the file’s creation and its path on Device1. To identify when the file was first detected: Open the file page from Entities: This page provides detailed information about the file, including the timestamp of when the file was first detected on Device1. You can access this information directly from the entities list related to the detection event.
upvoted 8 times
...
a_kto_to
Most Recent 1 week ago
ChatGTP see it this way: ✅ To identify the image file path Correct answer: Event entities graph The Event entities graph shows relationships and context around the detected activity — such as which process (with full path) executed the suspicious file, parent/child process relationships, etc. It's especially helpful when analyzing how the file was executed and where it resides. ✅ To identify when the file was first detected on Device1 Correct answer: Open the file page from Entities The Entities pane links you to detailed profiles of involved files, IPs, users, etc. When you open the file entity, you'll see information like first seen, prevalence, and detection history.
upvoted 1 times
...
Optimizor_IT
1 week, 5 days ago
To identify the image file path: Entities Reason: The “Entities” section of the event details provides the file path. To identify when the file was first detected: Action type Reason: The timeline event’s action type (e.g., “File observed”) ties to the timestamp, showing when the file was first seen (earliest event).
upvoted 2 times
Adel614
1 week ago
Yes, the key element to answer the option 2 is "What should you REVIEW from the TIMELINE...". We have to use the time line of the alert. Therefore, the graph answer is misleading.
upvoted 1 times
...
...
HAjouz
1 month, 3 weeks ago
To identify the image file path: Entities: This is the correct choice. The "Entities" section in a Microsoft Defender for Endpoint timeline provides detailed information about the file, including its full path. To identify when the file was first detected: Action type: This is the correct choice. The "Action type" section in a Microsoft Defender for Endpoint timeline includes the timestamp of the first detection event.
upvoted 1 times
...
sapphire
5 months, 1 week ago
Correct answers.
upvoted 2 times
...
g_man_rap
8 months ago
To identify the image file path: The correct answer is Entities because the entity information includes the file path. To identify when the file was first detected: The correct answer is Action type since it records the specific actions taken at various points, including the initial detection of the file.
upvoted 1 times
...
smanzana
8 months, 3 weeks ago
Event entities graph Entities
upvoted 1 times
...
Avaris
10 months, 2 weeks ago
here is the answer from copilot which makes this answer correct Based on the information provided in the image, to investigate a suspicious executable file detected on Device1 and meet the requirements: To identify the image file path of the file, you should review the Entities from the timeline of the detection event. To identify when the file was first detected on Device1, you should review the Event entities graph from the timeline of the detection event. These options will provide the necessary details about the suspicious file’s location on the device and the timeline of its detection, which are crucial for a thorough investigation. Always ensure to verify such information from trusted sources or directly from the service provider for security reasons. If you have any further questions or need additional assistance, feel free to ask!
upvoted 1 times
...
wheeldj
11 months, 3 weeks ago
These answers are the wrong way round. To identify the image file path -> Event entities graph To identify when the file was first seen -> open the file page from Entities
upvoted 4 times
Hawklx
10 months ago
The Event entities graph can also be useful for visualizing the relationships between different entities related to the alert. However, it might not directly show the image file path.
upvoted 1 times
Hawklx
9 months, 1 week ago
Actually I was wrong, the order is like other suggested
upvoted 1 times
...
...
Simboti
11 months, 3 weeks ago
can you share the link please
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago