Microsoft Security Operations Analyst Associate SC-200 Practice Question
You plan to use the native deception capability in Microsoft Defender XDR to detect lateral-movement attempts that rely on harvesting local administrator credentials from Windows 10 endpoints.
You create a new deception rule that deploys a credential lure (honeytoken) and assign the rule to a device group that contains 50 Windows 10 21H2 computers.
While configuring the rule, which setting must you enable so that the lure is actually written into LSASS on the targeted devices and an alert is generated if the credentials are used on another device?
Select Local Administrator credential type instead of Domain Administrator.
Increase the maximum number of targeted devices to more than 100.
For a credential-lure deception rule to be active on the selected devices, you must set the rule's Enforce state to 'On'. If the rule is left in Audit (also called 'Report only') mode, Defender XDR records policy applicability but does not deposit the fake credential in LSASS, so no alert will ever fire when the lure is used. The rule scope (device group) and the lure type are defined elsewhere in the wizard and do not by themselves cause the credential to be deployed. Selecting an assignment method of automatic or manual determines how devices are added to the rule but likewise has no effect unless enforcement is enabled.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is LSASS in Windows, and what role does it play in credential harvesting?
Open an interactive chat with Bash
What is a credential lure or honeytoken in cybersecurity, and how does it work?
Open an interactive chat with Bash
What does changing a deception rule mode to Enforce in Microsoft Defender XDR achieve?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .