MS-102 Practice Question 3073
Exam: MS-102
Domain: Manage security and threats using Microsoft Defender XDR
Difficulty: hard
In Microsoft Defender for Identity, what is the primary purpose of designating sensitive accounts and configuring "Honeypot" decoy user accounts?
Answer Options
A
To detect unauthorized reconnaissance and lateral movement using decoy assets
B
To automatically reset passwords for executive users every 2 hours
C
To reduce the storage space required for Active Directory databases
D
To allow guest users to manage Azure subscriptions
Correct Answer
A: To detect unauthorized reconnaissance and lateral movement using decoy assets
Explanation
Honeypot accounts are decoys with no legitimate operational purpose; any authentication attempt against a honeypot account is immediately flagged as malicious reconnaissance.