Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Identity. You need to configure a honeytoken account to detect attackers trying to use the account. In which location should you place the honeytoken account?

⚠ Common exam trap

Many exam-takers assume a honeytoken must have high privileges to be attractive to attackers, but Microsoft Defender for Identity specifically requires a low-privilege account that no legitimate user would ever use, so any authentication is automatically suspicious.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A domain user account with no privileges

A honeytoken account in Microsoft Defender for Identity is designed to lure attackers by appearing as a real, low-privilege account that no legitimate user should ever authenticate with. Placing it as a domain user account with no privileges ensures that any authentication attempt using its credentials is suspicious and triggers an alert, because no legitimate activity should involve this account. This allows Defender for Identity to detect lateral movement or credential theft attempts without risking exposure of sensitive resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A domain user account with no privileges

    Why this is correct

    A domain user account with no privileges is the correct honeytoken because Microsoft Defender for Identity treats any authentication attempt using this account as suspicious. Since the account is a real Active Directory object, MDI can monitor and alert on its activity, and because it lacks any privileged group memberships or legitimate permissions, there is no valid reason for it to authenticate to any resource. This ensures that any authentication event involving the account is a high-confidence indicator of attacker activity, minimizing false positives while maximizing detection value.

  • ✗

    A service account with high privileges

    Why it's wrong here

    A service account with high privileges is wrong because it is expected to authenticate frequently to perform valid service operations, and its elevated permissions mean those authentications will occur across many systems and protocols. This volume of legitimate activity would drown out genuine attack signals and produce excessive false positives. Moreover, if this account were compromised, it would pose a real security risk because it has actual access rights, contradicting the purpose of a decoy honeytoken that should be useless to an attacker.

  • ✗

    A non-existent account alias in AD

    Why it's wrong here

    A non-existent account alias in Active Directory cannot be used as a honeytoken because Microsoft Defender for Identity only tracks actual directory objects; it has no mechanism to raise a specific honeytoken alert for a name that does not exist in the directory. While attempts to authenticate with a nonexistent account might trigger other MDI detections such as identity enumeration or brute-force suspicion, those are generic attack patterns and not the deliberate trap that a honeytoken provides. The honeytoken must be a real object that an attacker can potentially discover and attempt to abuse.

  • ✗

    A guest account

    Why it's wrong here

    A guest account is wrong because it is a built-in account that may be legitimately enabled or used in some environments, and its default configuration can vary, making it an unreliable sensor for attacker activity. The Guest account is often subject to password-related settings and can be used for anonymous or temporary access, so an authentication event from it could stem from benign administrative habits or sharing-misconfiguration rather than a targeted attack. This ambiguity would introduce false positives and makes it a poor choice for a decoy whose sole purpose is to sit unused and trigger only on malicious interaction.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.