A security administrator is hardening a fleet of Windows 10 endpoints against credential theft attacks such as Pass-the-Hash and credential dumping. Which TWO of the following measures directly mitigate these threats by protecting credentials in memory and restricting their use? (Choose two.)
Credential Guard uses virtualization-based security to isolate and protect derived domain credentials, such as NTLM hashes and Kerberos tickets, from being extracted by malware. It prevents pass-the-hash attacks by keeping these secrets in a secure container. This directly addresses credential theft and is a correct measure.
Why this answer
Credential Guard and LSA protection directly protect credentials in memory. Credential Guard isolates derived credentials using virtualization-based security, preventing their theft. LSA protection blocks non-PPL processes from reading LSA memory, thwarting credential dumping tools.
SMB signing, Windows Defender Firewall, and BitLocker address other security aspects but do not directly prevent credential theft from memory.
Exam trap
The trap here is selecting network or disk encryption controls that seem security-related but do not address in-memory credential protection.