Microsoft Security Operations Analyst (SC-200) Practice Question Bank — PracticeTrial (no sign-up)
Question 1 of 10Respond to security incidents (35–40%)
A responder finds a suspicious binary during a live response session and needs a copy for controlled offline analysis. Which live response operation should be used?