MS-102 Practice Question 3064

Exam: MS-102
Domain: Manage security and threats using Microsoft Defender XDR
Difficulty: medium
You are deploying Microsoft Defender for Identity across your on-premises domain controllers. What component must be installed directly on each domain controller to monitor network traffic and event logs?

Answer Options

A
The Microsoft Defender for Identity sensor installed on domain controllers
B
Microsoft Exchange Edge Transport role
C
Apache reverse proxy daemon
D
Azure Virtual Desktop host pool agent

Correct Answer

A: The Microsoft Defender for Identity sensor installed on domain controllers

Explanation

The Microsoft Defender for Identity sensor is installed directly on domain controllers and AD FS servers to parse authentication traffic and inspect security event logs.