SC-200 · Question #17
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…
The correct answer is A. Yes. Honeytoken accounts in Microsoft Defender for Identity are purpose-built decoy accounts. Any interaction with a honeytoken account (authentication attempts, enumeration, etc.) immediately triggers a high-confidence alert, because no legitimate user should ever touch these…
Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are configuring Microsoft Defender for Identity integration with Active Directory. From the Microsoft Defender for identity portal, you need to configure several accounts for attackers to exploit. Solution: From Entity tags, you add the accounts as Honeytoken accounts. Does this meet the goal?
Options
- AYes
- BNo
How the community answered
(55 responses)- A82% (45)
- B18% (10)
Explanation
Honeytoken accounts in Microsoft Defender for Identity are purpose-built decoy accounts. Any interaction with a honeytoken account (authentication attempts, enumeration, etc.) immediately triggers a high-confidence alert, because no legitimate user should ever touch these accounts. Configuring them via Entity tags > Honeytoken in the Defender for Identity portal is the correct and documented method, so the solution fully meets the stated goal.
Topics
Community Discussion
No community discussion yet for this question.