SC-200 · Question #96
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…
The correct answer is B. No. No, this does not meet the goal. The scenario describes setting up accounts for attackers to exploit as bait - this is a honeypot configuration. The correct feature in Microsoft Defender for Identity is 'Honeytoken accounts' (Honeytoken entities). Honeytokens are decoy accounts…
Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are configuring Microsoft Defender for Identity integration with Active Directory. From the Microsoft Defender for identity portal, you need to configure several accounts for attackers to exploit. Solution: You add each account as a Sensitive account. Does this meet the goal?
Options
- AYes
- BNo
How the community answered
(30 responses)- A23% (7)
- B77% (23)
Explanation
No, this does not meet the goal. The scenario describes setting up accounts for attackers to exploit as bait - this is a honeypot configuration. The correct feature in Microsoft Defender for Identity is 'Honeytoken accounts' (Honeytoken entities). Honeytokens are decoy accounts that should never be accessed by legitimate users, so any interaction with them triggers a high-confidence alert. 'Sensitive accounts,' by contrast, are real high-value accounts (e.g., executives, service accounts) that receive enhanced monitoring and stricter detection thresholds - they are protected accounts, not bait. These are two fundamentally different features.
Topics
Community Discussion
No community discussion yet for this question.