Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
02Microsoft Defender for Endpoint9 modules · 60 units · 5 hr 49 min · Deployment, attack surface reduction, investigations, response, automation, detections, and vulnerability management0/60 units complete
Learning path 02 · Microsoft Defender for Endpoint

9 modules · 60 units · 5 hr 49 min · Deployment, attack surface reduction, investigations, response, automation, detections, and vulnerability management

0%

Study focus

Endpoint readiness

Deploy, onboard, configure, and harden devices with Microsoft Defender for Endpoint.

Investigation and response

Investigate devices and evidence, take response actions, automate remediation, and tune detections.

9 modules · 60 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

05

Module 5

Perform actions on a device using Microsoft Defender for Endpoint

Focus: containment, antivirus scans, forensic packages, and Live Response.
0/7
01 / 07Introduction

Device actions support three goals: contain active attacker access, collect forensic evidence, and remediate malicious artifacts. Actions are tracked in the Action center and device timeline.

Official moduleResponse action objectives
02 / 07Explain device actions
ActionUse
Isolate deviceDisconnect network communication while retaining MDE service connectivity; limits command and control, exfiltration, and lateral movement.
Restrict app executionApply a code-integrity policy so only Microsoft-signed files can run.
Run antivirus scanRemotely run quick or full scanning.
Automated investigationStart analyst-like investigation and remediation.
Collect packageAcquire a point-in-time forensic ZIP.
Live ResponseOpen an authorized remote shell for investigation and response.
Official lessonContainment and investigation actions
03 / 07Run Microsoft Defender Antivirus scan on devices

Choose quick or full scan and document the reason. Scan submissions and resulting detections appear in the Action center, device timeline, and alert queue. Defender Antivirus can scan while in passive mode alongside another antivirus product. CPU throttling settings still apply.

A general-purpose automated investigation can be started from the device; related alerts and devices may be added while it is running.

Official lessonRemote scan and automated investigation
04 / 07Collect investigation package from devices

The package captures current forensic state: autoruns, installed programs, network connections and DNS/ARP data, prefetch, processes, scheduled tasks, security logs, services, SMB sessions, system details, temp-directory listings, users/groups, Defender support logs, and a collection summary report.

Exam takeaway: packages preserve endpoint state for offline analysis; they are not the same as the continuously collected device timeline.
Official lessonInvestigation package contents
05 / 07Initiate Live Response session

Live Response is a cloud-based remote shell for immediate investigation and remediation. Enable it in Advanced features, assign an appropriate device-group remediation level, and grant basic or advanced RBAC permissions. Unsigned scripts require a separate tenant setting and increase risk.

Basic examplesAdvanced examples
processes, services, scheduledtasks, persistence, registry, findfileanalyze, getfile, putfile, run, remediate, undo

Use -auto where supported to run prerequisites. Commands are audited. Large-scale execution is not supported, and session concurrency and inactivity limits apply.

Official lessonLive Response prerequisites and commands
06 / 07Module assessment

Choose containment actions according to objective: isolate network activity, restrict execution, scan for malware, collect evidence, automate investigation, or use Live Response for interactive work.

Official assessmentDevice actions knowledge check
07 / 07Summary and resources

Every response action should have a documented reason, least-privilege authorization, Action center verification, and a clear rollback or recovery plan where applicable.

Official moduleSummary and resources
End of learning pathMicrosoft Defender for Endpoint