exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 2 question 1 discussion

Actual exam question from Microsoft's MS-500
Question #: 1
Topic #: 2
[All MS-500 Questions]

DRAG DROP -
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Identity.
You receive the following alerts:
✑ Suspected Netlogon privilege elevation attempt
✑ Suspected Kerberos SPN exposure
✑ Suspected DCSync attack
To which stage of the cyber-attack kill chain does each alert map? To answer, drag the appropriate alerts to the correct stages. Each alert may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Select and Place:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: Compromised credential -
The following security alerts help you identify and remediate Compromised credential phase suspicious activities detected by Defender for Identity in your network.
In this tutorial, you'll learn how to understand, classify, remediate and prevent the following types of attacks:
Suspected Netlogon privilege elevation attempt (CVE-2020-1472 exploitation) (external ID 2411)
Suspected Kerberos SPN exposure (external ID 2410)
Etc.

Box 2: Compromised credential -

Box 3: Domain dominance -
The following security alerts help you identify and remediate Domain dominance phase suspicious activities detected by Defender for Identity in your network. In this tutorial, learn how to understand, classify, prevent, and remediate the following attacks:
Suspected DCSync attack (replication of directory services) (external ID 2006)
Etc.
Reference:
https://docs.microsoft.com/en-us/defender-for-identity/compromised-credentials-alerts https://docs.microsoft.com/en-us/defender-for-identity/domain-dominance-alerts

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Tanasi
1 year, 11 months ago
Suspected Netlogon privilege elevation attempt is Privilege escalation, but we do not have that option so Compromised Credentials is better. See here: https://learn.microsoft.com/en-us/defender-for-identity/alerts-overview
upvoted 1 times
...
Lomak
2 years, 6 months ago
Correct https://learn.microsoft.com/en-us/defender-for-identity/alerts-overview
upvoted 3 times
...
pete26
2 years, 7 months ago
Answers appears to be correct. Suspected DCSync attack (replication of directory services) (external ID 2006) is part of Domain Dominance. Suspected Kerberos SPN exposure (external ID 2410) AND Suspected Netlogon privilege elevation attempt (CVE-2020-1472 exploitation) (external ID 2411) are part of Compromised credentials.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago