SC-200 · Question #390
You have a Microsoft 365 E5 subscription. You need to ensure that an alert is generated in Microsoft Defender XDR when attackers attempt to connect to a specific device. The solution must minimize…
The correct answer is B. Tag an existing device as a honeytoken entity. To generate an alert in Microsoft Defender XDR when attackers attempt to connect to a specific device with minimal administrative effort, tag the device as a honeytoken entity.
Question
You have a Microsoft 365 E5 subscription. You need to ensure that an alert is generated in Microsoft Defender XDR when attackers attempt to connect to a specific device. The solution must minimize administrative effort. What should you do in the Microsoft Defender portal?
Options
- ACreate a deception rule that includes a decoy.
- BTag an existing device as a honeytoken entity.
- CCreate a deception rule that includes a lure.
- DTag an existing device as a sensitive entity.
How the community answered
(45 responses)- A18% (8)
- B71% (32)
- C4% (2)
- D7% (3)
Why each option
To generate an alert in Microsoft Defender XDR when attackers attempt to connect to a specific device with minimal administrative effort, tag the device as a honeytoken entity.
Creating a deception rule that includes a decoy is a broader concept for deception, but directly tagging an *existing* device as a honeytoken is the most straightforward and administratively minimal way to achieve the specific goal of alerting on interaction with that device.
Tagging an existing device as a honeytoken entity is a feature within Microsoft Defender XDR's deception capabilities. This configuration automatically generates high-severity alerts if any activity or connection attempt is made to that designated honeytoken device, serving as an early warning for attacker presence with minimal setup.
Creating a deception rule that includes a lure typically involves creating tempting artifacts (like files or credentials) on legitimate devices that, if accessed, trigger an alert, rather than directly alerting on connection attempts to a specific device itself.
Tagging an existing device as a sensitive entity helps prioritize its protection and monitoring but does not inherently trigger an alert solely based on connection attempts to it without additional custom detection rules or advanced hunting.
Concept tested: Microsoft Defender XDR honeytoken entities and deception
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-honeypots-microsoft-defender-for-endpoint?view=o365-worldwide
Community Discussion
No community discussion yet for this question.