nerdexam
Microsoft

SC-100 · Question #54

Your company has a Microsoft 365 subscription and uses Microsoft Defender for Identity. You are informed about incidents that relate to compromised identities. You need to recommend a solution to…

The correct answer is B. honeytoken entity tags. Honeytoken entities are used as traps for malicious actors. Any authentication associated with these honeytoken entities triggers an alert. https://docs.microsoft.com/en-us/defender-for-identity/entity-tags

Design security operations, identity, and compliance capabilities

Question

Your company has a Microsoft 365 subscription and uses Microsoft Defender for Identity. You are informed about incidents that relate to compromised identities. You need to recommend a solution to expose several accounts for attackers to exploit. When the attackers attempt to exploit the accounts, an alert must be triggered. Which Defender for Identity feature should you include in the recommendation?

Options

  • Astandalone sensors
  • Bhoneytoken entity tags
  • Csensitivity labels
  • Dcustom user tags

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    77% (23)
  • C
    3% (1)
  • D
    13% (4)

Explanation

Honeytoken entities are used as traps for malicious actors. Any authentication associated with these honeytoken entities triggers an alert. https://docs.microsoft.com/en-us/defender-for-identity/entity-tags

Topics

#Defender for Identity#Honeypot#Deception technology#Identity protection

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice