SC-100 · Question #269
Your network contains an Active Directory Domain Services (AD DS) domain named Domain1. You have a Microsoft Entra tenant. Domain1 syncs with the tenant by using Microsoft Entra Connect. You need to…
The correct answer is C. Microsoft Defender for Identity. Defender for Identity is fully integrated with Microsoft Defender XDR, and leverages signals from both on-premises Active Directory and cloud identities to help you better identify, detect, and investigate advanced threats directed at your organization. Note: Detecting and…
Question
Your network contains an Active Directory Domain Services (AD DS) domain named Domain1. You have a Microsoft Entra tenant. Domain1 syncs with the tenant by using Microsoft Entra Connect. You need to monitor Domain1 for privilege escalation attacks. What should you use?
Options
- AMicrosoft Entra ID Protection
- BMicrosoft Defender for Servers
- CMicrosoft Defender for Identity
- DPrivileged Identity Management (PIM)
How the community answered
(30 responses)- A3% (1)
- B20% (6)
- C70% (21)
- D7% (2)
Explanation
Defender for Identity is fully integrated with Microsoft Defender XDR, and leverages signals from both on-premises Active Directory and cloud identities to help you better identify, detect, and investigate advanced threats directed at your organization. Note: Detecting and preventing privilege escalation attacks leveraging Kerberos relaying (KrbRelayUp) Microsoft Defender for Identity detects activity from the early stages of the attack chain by monitoring anomalous behavior as seen by the domain controller. https://learn.microsoft.com/en-us/defender-for-identity/what-is escalation-attacks-leveraging-kerberos-relaying- krbrelayup/
Topics
Community Discussion
No community discussion yet for this question.