exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 1 question 22 discussion

Actual exam question from Microsoft's SC-100
Question #: 22
Topic #: 1
[All SC-100 Questions]

You have an Azure AD tenant that syncs with an Active Directory Domain Services (AD DS) domain. Client computers run Windows and are hybrid-joined to Azure AD.

You are designing a strategy to protect endpoints against ransomware. The strategy follows Microsoft Security Best Practices.

You plan to remove all the domain accounts from the Administrators groups on the Windows computers.

You need to recommend a solution that will provide users with administrative access to the Windows computers only when access is required. The solution must minimize the lateral movement of ransomware attacks if an administrator account on a computer is compromised.

What should you include in the recommendation?

  • A. Local Administrator Password Solution (LAPS)
  • B. Azure AD Identity Protection
  • C. Azure AD Privileged Identity Management (PIM)
  • D. Privileged Access Workstations (PAWs)
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
zellck
Highly Voted 1 year, 11 months ago
Selected Answer: A
A is the answer. https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-overview Windows Local Administrator Password Solution (Windows LAPS) is a Windows feature that automatically manages and backs up the password of a local administrator account on your Azure Active Directory-joined or Windows Server Active Directory-joined devices. You also can use Windows LAPS to automatically manage and back up the Directory Services Restore Mode (DSRM) account password on your Windows Server Active Directory domain controllers. An authorized administrator can retrieve the DSRM password and use it.
upvoted 8 times
zellck
1 year, 11 months ago
Gotten this in May 2023 exam.
upvoted 2 times
...
...
yarvis
Highly Voted 2 years, 2 months ago
Selected Answer: A
LAPS - https://learn.microsoft.com/en-us/security/compass/incident-response-playbook-dart-ransomware-approach
upvoted 5 times
...
P1mp
Most Recent 5 months, 1 week ago
Selected Answer: A
Implement LAPS to securely manage and randomize local administrator passwords. This ensures administrative access is provided securely and minimizes the risk of lateral movement in the event of an account compromise.
upvoted 1 times
...
Dirkonormalo
5 months, 4 weeks ago
Selected Answer: C
I configured that with pim too. We decided against laps, because we wanted personalized accounts in central audit with justification. Ites confusing me
upvoted 2 times
...
keithtemplin
8 months, 1 week ago
Selected Answer: C
You add an empty domain group to the local admins group. You use Azure PIM to provide JITA membership to that group. https://techcommunity.microsoft.com/t5/intune-customer-success/configuring-microsoft-intune-just-in-time-admin-access-with/ba-p/3843972
upvoted 2 times
...
besoaus
10 months, 1 week ago
I'm confused, Why not "C"? PIM will allow us to apply the same, and we can give also "Just in time" Access. And it will eliminate Lateral movement
upvoted 3 times
...
[Removed]
1 year, 1 month ago
Selected Answer: D
PAWs are specifically designed to minimize the risk of lateral movement by segregating administrative tasks to dedicated workstations. Admins use these workstations solely for privileged activities, reducing the chances of exposing credentials in less secure environments. This strategy helps to contain and limit the impact of compromised administrator accounts on regular workstations.
upvoted 1 times
Zabulon777
1 year, 1 month ago
Wrong as you are not going to deploy PAW machines to every employee in the company. It specifies changing the administrator account on all machines which LAPS does. Answers is A
upvoted 1 times
...
...
Ramye
1 year, 3 months ago
The more I read about LAPS the more confusing it is. https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-scenarios-azure-active-directory
upvoted 2 times
...
JG56
1 year, 5 months ago
LAPS is the answer, in exam Nov 23
upvoted 3 times
...
Kvoth3
1 year, 8 months ago
What about D. To provide users with administrative access to the Windows computers only when access is required, you can use Privileged Access Workstations (PAWs). PAWs are dedicated operating systems for sensitive tasks that are protected from Internet attacks and threat vectors. They separate these sensitive tasks and accounts from the daily use workstations and devices, providing strong protection from phishing attacks, application and OS vulnerabilities, various impersonation attacks, and credential theft attacks such as keystroke logging, Pass-the-Hash, and Pass-The-Ticket 1. PAWs can be used to minimize the lateral movement of ransomware attacks if an administrator account on a computer is compromised. PAWs provide a secure environment for administrative tasks that require elevated privileges. They are designed to protect against advanced persistent threats (APTs) and other sophisticated attacks.
upvoted 4 times
nExoR
1 year, 4 months ago
PAWs are administration workstations. concept from totally different area. the question asks about users having access on their regular workstations - e.g. to install app. not some specialized, isolated workstation
upvoted 1 times
...
...
Ario
1 year, 10 months ago
for those check discussions don't be fool by most rated answers .
upvoted 4 times
Baz10
1 year, 1 month ago
Hahah leaving a riddle and then dipping smh
upvoted 2 times
...
Bondaexam
1 year, 5 months ago
what should be the final judgement when multiple answers are chosen by multiple people . Dont tell us to go back and look into the documentation, we all know that . What should be the final judgement???
upvoted 1 times
...
...
Itu2022
1 year, 10 months ago
was on exam 15/06/23
upvoted 2 times
...
edurakhan
1 year, 11 months ago
On exam 5/25/2023
upvoted 2 times
...
init2winit
2 years ago
Selected Answer: A
Agree with A, as Yarvis pointed out in the link. For endpoint administrative management, use the local administrative password solution (LAPS).
upvoted 2 times
...
Bouncy
2 years, 2 months ago
Selected Answer: A
A, but only because the others don't make sense. If you ever need to remove admins from PCs in real life, do not use LAPS. Use Microsoft Intune Endpoint Privilege Management instead. It lets you decide precisely for which action users may receive an elevation, whereas LAPS will give users full local admin access until the password changes - which can take days or even weeks in reality...
upvoted 4 times
ARYMBS
1 year, 7 months ago
This does not work on Hybrid AzureAD Joined....
upvoted 1 times
jasscomp
1 year, 7 months ago
Incorrect - it does work on HAADJ devices - worked for me https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-overview#understand-device-join-state-restrictions
upvoted 1 times
...
...
...
mynk29
2 years, 3 months ago
Selected Answer: A
Granting users access to their PC is not the typical use case for LAPS- admins use it for troubleshooting/as a break glass account. But PIM is explicitly not meant to do it. see https://www.reddit.com/r/Intune/comments/yqdiyf/azure_ad_joined_device_local_admin_via_pim/ PAW and Identity protection are not relevant so will reluctantly go with A.
upvoted 3 times
...
Jacquesvz
2 years, 3 months ago
Selected Answer: A
Agree with A, check this link for reason - https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-guide-how-to-configure-microsoft-local/ba-p/2806185
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago