nerdexam
Microsoft

SC-200 · Question #96

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is B. No. No, this does not meet the goal. The scenario describes setting up accounts for attackers to exploit as bait - this is a honeypot configuration. The correct feature in Microsoft Defender for Identity is 'Honeytoken accounts' (Honeytoken entities). Honeytokens are decoy accounts…

Submitted by yuriko_h· Apr 18, 2026Configure protections and detections

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are configuring Microsoft Defender for Identity integration with Active Directory. From the Microsoft Defender for identity portal, you need to configure several accounts for attackers to exploit. Solution: You add each account as a Sensitive account. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(30 responses)
  • A
    23% (7)
  • B
    77% (23)

Explanation

No, this does not meet the goal. The scenario describes setting up accounts for attackers to exploit as bait - this is a honeypot configuration. The correct feature in Microsoft Defender for Identity is 'Honeytoken accounts' (Honeytoken entities). Honeytokens are decoy accounts that should never be accessed by legitimate users, so any interaction with them triggers a high-confidence alert. 'Sensitive accounts,' by contrast, are real high-value accounts (e.g., executives, service accounts) that receive enhanced monitoring and stricter detection thresholds - they are protected accounts, not bait. These are two fundamentally different features.

Topics

#Microsoft Defender for Identity#Honeypot accounts#Sensitive accounts#Threat detection configuration

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice