SC-200 · Question #365
You have a Microsoft 365 subscription that contains a user named User1 and two Windows devices named Device1 and Device2. Device1 and Device2 are onboarded to Microsoft Defender for Endpoint. The…
The correct answer is F. RDP, RPC, and SMB. When automatic attack disruption contains a user in Microsoft Defender XDR, Device2 will block all common remote access protocols (RDP, RPC, and SMB) for User1 to prevent lateral movement.
Question
You have a Microsoft 365 subscription that contains a user named User1 and two Windows devices named Device1 and Device2. Device1 and Device2 are onboarded to Microsoft Defender for Endpoint. The following events occur.
- User1 signs in to Device1.
- Automatic attack disruption in Microsoft Defender XDR responds to an
attack on Device1 and contains User1.
- User1 attempts to connect to Device2.
Which protocols will Device2 block when User1 attempts to connect to Device2?
Options
- ARDP only
- BRPC only
- CSMB only
- DRDP and RPC only
- ESMB and RPC only
- FRDP, RPC, and SMB
How the community answered
(49 responses)- A14% (7)
- B2% (1)
- C6% (3)
- D4% (2)
- F73% (36)
Why each option
When automatic attack disruption contains a user in Microsoft Defender XDR, Device2 will block all common remote access protocols (RDP, RPC, and SMB) for User1 to prevent lateral movement.
This is incorrect because automatic attack disruption blocks more than just RDP to prevent lateral movement.
This is incorrect because automatic attack disruption blocks more than just RPC to prevent lateral movement.
This is incorrect because automatic attack disruption blocks more than just SMB to prevent lateral movement.
This is incomplete; SMB is also blocked as part of comprehensive user containment.
This is incomplete; RDP is also blocked as part of comprehensive user containment.
Microsoft Defender XDR's automatic attack disruption, when containing a user, blocks all major lateral movement protocols, including RDP, RPC, and SMB, to prevent the compromised user account from accessing other devices in the network.
Concept tested: Microsoft Defender XDR automatic attack disruption user containment
Source: learn.microsoft.com/microsoft-365/security/defender/automatic-attack-disruption
Community Discussion
No community discussion yet for this question.