exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 2 question 14 discussion

Actual exam question from Microsoft's MS-500
Question #: 14
Topic #: 2
[All MS-500 Questions]

Your network contains an on-premises Active Directory domain. The domain contains the servers shown in the following table.

You plan to implement Microsoft Defender for Identity for the domain.
You install a Microsoft Defender for Identity standalone sensor on Server1.
You need to monitor the domain by using Microsoft Defender for Identity.
What should you do?

  • A. Configure port mirroring for Server1.
  • B. Install the Microsoft Monitoring Agent on DC1.
  • C. Install the Microsoft Monitoring Agent on Server1.
  • D. Configure port mirroring for DC1.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
KarimaMaf
1 year, 11 months ago
https://learn.microsoft.com/en-us/defender-for-identity/configure-port-mirroring
upvoted 1 times
...
Maxx4
1 year, 11 months ago
Selected Answer: B
To monitor the domain using Microsoft Defender for Identity after installing the standalone sensor on Server1, you should: B. Install the Microsoft Monitoring Agent on DC1. Microsoft Defender for Identity requires the Microsoft Monitoring Agent to be installed on the domain controllers (DCs) in order to collect security-related events and data from the Active Directory environment. In this scenario, since Server1 is a member server, installing the Microsoft Monitoring Agent on Server1 (option C) would not fulfill the requirement of monitoring the domain. Configuring port mirroring for Server1 (option A) or configuring port mirroring for DC1 (option D) would not be the appropriate steps for monitoring the domain using Microsoft Defender for Identity. Port mirroring is typically used to capture network traffic and send it to a monitoring or security appliance for analysis, but it is not directly related to Microsoft Defender for Identity functionality. Therefore, the correct action to monitor the domain using Microsoft Defender for Identity after installing the standalone sensor on Server1 is to install the Microsoft Monitoring Agent on DC1 (option B)
upvoted 2 times
...
Unicorn02
2 years, 6 months ago
D is correct. Taken from: https://learn.microsoft.com/en-us/defender-for-identity/prerequisites "The Defender for Identity standalone sensor is installed on a dedicated server and requires port mirroring to be configured on the domain controller to receive network traffic."
upvoted 2 times
...
Snaileyes
2 years, 8 months ago
It's tricky though, because Microsoft recommends deploying the "Defender for Identity" sensor on DC's "For full coverage of your environment, we recommend deploying the Defender for Identity sensor." This is from the note at the reference link... Answer is D though, since question specifies the Standalone sensor...
upvoted 1 times
...
pete26
2 years, 8 months ago
Selected Answer: D
D is correct!
upvoted 4 times
JimboJones99
2 years, 8 months ago
Yes, the agent can't be installed on a DC
upvoted 3 times
Anonymousse
2 years, 8 months ago
uh, https://learn.microsoft.com/en-us/defender-for-identity/prerequisites According to this, the sensor must be installed on a DC or AD FS server.
upvoted 2 times
Anonymousse
2 years, 8 months ago
However, the link in the original answer states installing on a standalone sensor. So it can be installed on a DC or Standalone server.
upvoted 1 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...