SC-200 Web TestEngine demo

Exit VCEDump SC-200 Microsoft Security Operations Analyst
Question 53 of 61
0% complete
Q53 Single choice

You have 1,000 on-premises Windows 11 Pro devices that are onboarded to Microsoft Defender for Endpoint.

You have a Microsoft 365 subscription that uses Microsoft Defender XDR.

You identify that an attacker performed the following actions on a device:

1. Modified the filesystem path of a registry-based antivirus exclusion
2. Downloaded a malicious file to the file system path

You initiate a live response session on the device.

You need to undo the registry change.

Which command should you run?

Sign in to mark questions

Sign in to save marked questions and return to this demo.

Sign in