SC-100 · Question #146
You are a security administrator for Microsoft 365; you implemented Microsoft Defender for Identity You have created several test accounts with specific configurations for the purpose of vulnerability
The correct answer is D. Honeytoken entity tags. Honeytoken entity tags are decoy accounts deliberately created to lure attackers. When any authentication attempt or interaction occurs against a honeytoken account, Microsoft Defender for Identity immediately raises a high-priority alert, revealing attacker tactics and the areas
Question
You are a security administrator for Microsoft 365; you implemented Microsoft Defender for Identity You have created several test accounts with specific configurations for the purpose of vulnerability testing, When attackers try to exploit these accounts, you would like to be alerted to see what areas in the configuration needs improvements. What features in Microsoft Defender for Identity can you use to meet your objective?
Options
- ASensitivity labels
- BSystem user tags
- CConfidential label
- DHoneytoken entity tags
How the community answered
(57 responses)- A4% (2)
- B5% (3)
- C11% (6)
- D81% (46)
Explanation
Honeytoken entity tags are decoy accounts deliberately created to lure attackers. When any authentication attempt or interaction occurs against a honeytoken account, Microsoft Defender for Identity immediately raises a high-priority alert, revealing attacker tactics and the areas of your environment being probed. Sensitivity labels (A) and Confidential labels (C) are Microsoft Purview data-classification features unrelated to Defender for Identity. System user tags (B) are built-in Defender for Identity tags applied to service and sensitive accounts for tracking, not for deception-based alerting.
Topics
Community Discussion
No community discussion yet for this question.