SC-200 Practice Question 3689
Exam: SC-200
Domain: Manage a security operations environment
Difficulty: medium
In Microsoft Defender for Identity, what account type must be configured in directory services to query and resolve entities and track active domain membership?
Answer Options
A
A Group Managed Service Account (gMSA)
B
A Domain Administrator account with a simple password
C
An anonymous guest user account
D
A local computer guest account
Correct Answer
A: A Group Managed Service Account (gMSA)
Explanation
A Directory Service Account (DSA) using a standard Group Managed Service Account (gMSA) is recommended to query Active Directory domain objects securely.