SC-900 Practice Test 24 Hard Questions

SC-900 Exam Practice Test 24 (Hard) - Microsoft Defender for Identity and Cloud Apps Deep-Dive

SC-900 Exam Practice Tests

1 / 15

Which Microsoft Defender for Identity component is installed on-premises, directly on domain controllers, to monitor Active Directory traffic for signs of compromise?

2 / 15

Which Microsoft Defender for Identity detection type identifies an attacker attempting to use a stolen password hash to authenticate without knowing the actual plaintext password?

3 / 15

Which Microsoft Defender for Identity capability visually maps out potential paths an attacker could take to reach a highly sensitive account, such as a Domain Admin, from a compromised low-privilege account?

4 / 15

Which Microsoft Defender for Identity detection category identifies early-stage attacker activity, such as scanning the network or enumerating user accounts, before an actual compromise attempt occurs?

5 / 15

Which Microsoft Defender for Identity detection category identifies techniques an attacker uses to maintain persistent, high-level control over a compromised domain, such as forging Kerberos tickets?

6 / 15

Which Microsoft Defender for Cloud Apps deployment method connects directly to a sanctioned cloud app's API, enabling deep visibility and control, such as retroactive scanning of files already stored in that app?

7 / 15

Which Microsoft Defender for Cloud Apps capability provides real-time session control and monitoring for cloud app usage, such as blocking a download from an unmanaged device, without requiring a native API connector?

8 / 15

Which Microsoft Defender for Cloud Apps feature analyzes firewall and proxy log data to identify all the cloud applications actually being used within an organization, including unsanctioned ones?

9 / 15

Which Microsoft Defender for Cloud Apps feature assigns a risk score to discovered cloud applications, based on factors such as security certifications and data handling practices, helping prioritize which apps to sanction or block?

10 / 15

Which Microsoft Defender for Cloud Apps policy type would automatically alert an administrator if a user downloads an unusually large volume of files from a sanctioned cloud storage app within a short period?

11 / 15

Which Microsoft Defender for Cloud Apps feature evaluates third-party OAuth applications that have been granted permissions to access organizational data, flagging those with excessive or risky permission scopes?

12 / 15

Which term describes an attacker forging a Kerberos ticket-granting ticket to gain unrestricted, persistent access to an Active Directory domain, a technique specifically detected by Microsoft Defender for Identity's domain dominance capabilities?

13 / 15

Which term describes the process by which Microsoft Defender for Cloud Apps establishes a normal behavioral baseline for a specific user, enabling it to later detect deviations that could indicate compromise?

14 / 15

Which Microsoft Defender for Identity capability would flag a service account, which normally only ever logs in from a single specific server, suddenly authenticating interactively from an unusual workstation?

15 / 15

Which term describes the overall category of solution, encompassing products like Defender for Cloud Apps, that provides visibility, data security, and threat protection specifically for an organization's use of cloud applications?

Your score is

The average score is 0%

0%