Microsoft Security Operations Analyst Associate SC-200 Practice Question
You are investigating a Pass-the-Ticket alert raised by Microsoft Defender for Identity in the Microsoft Defender portal. The alert shows the service account svc-sql01 requesting Kerberos tickets for many resources in a short period, originating from the server SRV-APP01. No legitimate maintenance was scheduled. To block any further lateral movement while still allowing incident responders to gather evidence, which response action should you initiate directly from the alert page?
Suspend the svc-sql01 user account in Active Directory by using the Suspend user in Active Directory response action.
Isolate SRV-APP01 from the network by using Microsoft Defender for Endpoint.
Trigger a Kerberos ticket cache purge on the domain controller hosting SRV-APP01.
Reset the machine account password for SRV-APP01 by using remote PowerShell.
Microsoft Defender for Identity surfaces the Suspend user in Active Directory response action. Suspending the svc-sql01 account immediately blocks new Kerberos authentications but leaves the account intact, preserving forensic evidence. Although the Isolate device action is also available, it targets the host and could disrupt evidence collection on SRV-APP01. Resetting the computer account password affects only the machine account, and purging the Kerberos ticket cache on a domain controller cannot be triggered from the portal.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Pass-the-Ticket attack in cybersecurity?
Open an interactive chat with Bash
Why is suspending the user account better than isolating the device during such an alert?
Open an interactive chat with Bash
What is the purpose of purging Kerberos ticket caches in this scenario?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .