MS-102 Practice Question 3073

Exam: MS-102
Domain: Manage security and threats using Microsoft Defender XDR
Difficulty: hard
In Microsoft Defender for Identity, what is the primary purpose of designating sensitive accounts and configuring "Honeypot" decoy user accounts?

Answer Options

A
To detect unauthorized reconnaissance and lateral movement using decoy assets
B
To automatically reset passwords for executive users every 2 hours
C
To reduce the storage space required for Active Directory databases
D
To allow guest users to manage Azure subscriptions

Correct Answer

A: To detect unauthorized reconnaissance and lateral movement using decoy assets

Explanation

Honeypot accounts are decoys with no legitimate operational purpose; any authentication attempt against a honeypot account is immediately flagged as malicious reconnaissance.