SC-200 Respond to security incidents • Set 21
SC-200 Respond to security incidents Practice Test 21 — 15 questions with explanations. Free, no signup.
Your organization uses Microsoft Defender for Identity and Microsoft Defender XDR. You receive an alert about a suspicious LDAP query originating from a domain controller. The alert indicates potential use of the DCSync attack technique. What is the most effective immediate action to contain the attack?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.