Skip to content
SC-200
Respond to security incidents
hard
Question 2 of 73

A device shows suspicious behavior, and the responder must inspect artifacts and run approved remote investigation commands without physically accessing the machine. Which action should the responder take first?

AStart a live response session
BCreate a workbook
CChange Sentinel data retention
DRun an access review

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion