exam questions

Exam MS-100 All Questions

View all questions & answers for the MS-100 exam

Exam MS-100 topic 2 question 38 discussion

Actual exam question from Microsoft's MS-100
Question #: 38
Topic #: 2
[All MS-100 Questions]

Your network contains an on-premises Active Directory domain.
Your company has a security policy that prevents additional software from being installed on domain controllers.
You need to monitor a domain controller by using Microsoft Azure Advanced Threat Protection (ATP).
What should you do? More than once choice may achieve the goal. Select the BEST answer.

  • A. Deploy an Azure ATP standalone sensor, and then configure port mirroring.
  • B. Deploy an Azure ATP standalone sensor, and then configure detections.
  • C. Deploy an Azure ATP sensor, and then configure detections.
  • D. Deploy an Azure ATP sensor, and then configure port mirroring.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Piper
Highly Voted 5 years, 6 months ago
This I am quite sure is wrong, a standalone sensor is the only option with port mirroring. Because you cant install agents on DC's, the answer provided is wrong (in my opinion). I am happy if someone wishes to challenge that.
upvoted 49 times
Alvaroll
4 years, 8 months ago
Completely agree. https://practical365.com/security/azure-atp-intro/ "If you don’t want to deploy the Azure ATP Sensor directly on your domain controllers, you can instead deploy the Azure ATP Standalone Sensor on a separate server. The standalone sensor monitors traffic that you direct to it by using port mirroring on your network switches."
upvoted 6 times
VTHAR
4 years, 7 months ago
Yes. Correct answer is A. Same question in MS-101.
upvoted 8 times
...
[Removed]
4 years, 4 months ago
Agreed
upvoted 1 times
...
...
...
mshorty
Highly Voted 5 years, 4 months ago
I agree with @PlasticMind. Azure ATP Sensor will be installed on DC which is in this case not allowed (answers C and D). Azure ATP standalon sensor with port mirroring must be the correct answer (A). See here https://docs.microsoft.com/en-us/azure-advanced-threat-protection/atp-capacity-planning#choosing-the-right-sensor-type-for-your-deployment
upvoted 9 times
...
BigDazza_111
Most Recent 2 years ago
I hope the exam questions are clearer that this. The way i read it is, the company has a secuirty policy (writen) not configured, to not install any app on DC. And we need to use aATP sensor to monitor and report on this...the scenario does not specify that that it need to be monitored from the DC, but answer is indicated this was in the mind of the question creator.
upvoted 1 times
...
ijarosova
2 years, 2 months ago
Selected Answer: A
I vote A.
upvoted 1 times
...
jaysoft
2 years, 5 months ago
Selected Answer: A
If you don’t want to deploy the Azure ATP Sensor directly on your domain controllers, you can instead deploy the Azure ATP Standalone Sensor on a separate server. The standalone sensor monitors traffic that you direct to it by using port mirroring on your network switches. https://practical365.com/azure-atp-intro/
upvoted 2 times
...
Arlecchino
2 years, 8 months ago
Selected Answer: A
A is the way imo
upvoted 1 times
...
aaron_roman
2 years, 10 months ago
Selected Answer: A
no doubt A
upvoted 1 times
...
sliix
3 years, 3 months ago
Selected Answer: A
This is the answer. Trust me bro :)
upvoted 2 times
AlexLiourtas
3 years, 3 months ago
source: "dude trust me"
upvoted 20 times
...
...
tf444
3 years, 5 months ago
If you're installing on a domain controller, you don't need a standalone ATP sensor. You need to configure the detections to detect application installations. With an ATP sensor (non-standalone), you don't need to configure port mirroring. Reference: https://docs.microsoft.com/en-us/azure-advanced-threat-protection/install-atp-step5 https://docs.microsoft.com/en-us/azure-advanced-threat-protection/atp-capacity-planning#choosing-the-right-sen
upvoted 1 times
mikaiwhodakno
2 years, 11 months ago
As stated in the question: Your company has a security policy that prevents additional software from being installed on domain controllers. No install means it is installed elsewhere and monitors this server, answer A.
upvoted 3 times
...
...
08twitch
3 years, 5 months ago
Selected Answer: A
Update answer to A
upvoted 3 times
...
AlexLiourtas
3 years, 5 months ago
Selected Answer: A
A, you cannot install on active directory due to policy
upvoted 1 times
...
zacmzee
3 years, 7 months ago
I'll go with A, since in the question it states "Your company has a security policy that prevents additional software from being installed on domain controllers." That being said you can install Azure ATP standalone sensor on domain controller.
upvoted 1 times
...
Panku
3 years, 8 months ago
Answer should be A We cannot install additional software on the domain controllers. Azure ATP Standalone Sensor is a full agent installed on a dedicated server that can monitor traffic from multiple domain controllers. This is an alternative to those that do not wish to install an agent directly on a domain controller.
upvoted 2 times
...
jeffyeh
3 years, 8 months ago
From here looks like the "Azure ATP Sensor" is feasible to install on DC. So I'll go with C. https://docs.microsoft.com/en-us/defender-for-identity/install-step4
upvoted 1 times
mikaiwhodakno
2 years, 11 months ago
but the question states clearly: Your company has a security policy that prevents additional software from being installed on domain controllers.
upvoted 1 times
...
...
lengySK
3 years, 8 months ago
I think correct is A
upvoted 1 times
...
Azreal_75
3 years, 9 months ago
Does a stand-alone sensor even exist now? I can;t see any reference to it in the MS install guides?
upvoted 2 times
Paolo2022
2 years, 5 months ago
I found this (current) reference in MS Learn: https://learn.microsoft.com/en-us/defender-for-identity/configure-port-mirroring Also, I do think that A is the correct answer.
upvoted 1 times
...
...
mkuczynski
3 years, 10 months ago
It's a tricky question. We need to install ATP to fulfill the security policy. In this way C is correct answer.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...