nerdexam
Microsoft

SC-200 · Question #17

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is A. Yes. Honeytoken accounts in Microsoft Defender for Identity are purpose-built decoy accounts. Any interaction with a honeytoken account (authentication attempts, enumeration, etc.) immediately triggers a high-confidence alert, because no legitimate user should ever touch these…

Submitted by packet_pusher· Apr 18, 2026Configure protections and detections

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are configuring Microsoft Defender for Identity integration with Active Directory. From the Microsoft Defender for identity portal, you need to configure several accounts for attackers to exploit. Solution: From Entity tags, you add the accounts as Honeytoken accounts. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(55 responses)
  • A
    82% (45)
  • B
    18% (10)

Explanation

Honeytoken accounts in Microsoft Defender for Identity are purpose-built decoy accounts. Any interaction with a honeytoken account (authentication attempts, enumeration, etc.) immediately triggers a high-confidence alert, because no legitimate user should ever touch these accounts. Configuring them via Entity tags > Honeytoken in the Defender for Identity portal is the correct and documented method, so the solution fully meets the stated goal.

Topics

#Microsoft Defender for Identity#Honeytoken accounts#Threat detection#Entity tags

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice