MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Identity. You need to investigate an alert indicating a suspected lateral movement using pass-the-hash from a compromised workstation. Which entity should you prioritize examining in the investigation timeline?
⚠ Common exam trap
The trap here is that candidates often focus on the physical or network location (workstation or server) rather than the logical identity (the account) that carries the stolen hash across systems.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The compromised account
In a pass-the-hash (PtH) attack, the attacker uses the NTLM hash of a compromised account to authenticate to other systems. Microsoft Defender for Identity correlates the account's authentication events across multiple machines, so examining the compromised account in the investigation timeline reveals the full scope of lateral movement, including which workstations and servers were accessed using the stolen hash.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The source workstation
Why it's wrong here
The source workstation is only the initial foothold where the attacker extracted the NTLM hash from LSASS memory; it is not the primary entity because pass-the-hash allows the attacker to replay that hash from any host. Focusing solely on the source machine would miss lateral movement attempts originating from other systems using the same compromised account. Defender for Identity correlates account-based activities, not just per-device events, so the investigation should pivot to the identity rather than the specific workstation.
- ✗
The destination server
Why it's wrong here
The destination server is the target of the lateral movement attempt, where the replayed hash is presented to validate authentication. While examining it reveals which resources were accessed or whether the attack succeeded, it only shows one hop in the attack chain. The same compromised account could have been used against many other destination servers, so the account's authentication patterns and access history provide the full scope; the destination server alone is insufficient for the investigation.
- ✓
The compromised account
Why this is correct
The compromised account is the correct primary entity because pass-the-hash attacks abuse the NTLM hash of a user's password, allowing the attacker to authenticate as that user without knowing the plaintext. This account is the common thread across every lateral movement event, regardless of which source workstation or destination server is involved. Defender for Identity flags suspicious account activities such as anomalous sign-ins, TGT requests, or usage of the same hash from multiple hosts, making the account the central entity to correlate and trace in the investigation.
- ✗
The network segment
Why it's wrong here
The network segment is too broad and descriptive of the environment rather than the attack itself. Pass-the-hash is an identity-based attack, and Defender for Identity operates on Active Directory data and authentication signals, not on raw network traffic or segmentation boundaries. Investigating a network segment could encompass many unrelated hosts and users while failing to highlight the specific compromised identity that is replaying hashes; therefore, this focus would dilute the investigation and delay identifying the actual attacker's foothold.
Go deeper
Related to this question
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.