Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Fabrikam uses Microsoft Entra ID P2 and Microsoft Defender for Identity. The security operations team wants to detect and respond to suspicious activities such as pass-the-hash attacks and reconnaissance attempts against on-premises Active Directory Domain Services (AD DS) domain controllers. They need a solution that provides behavioral analytics and integrates with Microsoft Sentinel for incident correlation. What should you include in the design?

⚠ Common exam trap

Many exam-takers confuse Microsoft Entra ID Protection, which focuses on cloud identity risks, with Microsoft Defender for Identity, which monitors on-premises Active Directory Domain Services for advanced attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy Microsoft Defender for Identity sensors on domain controllers and configure Microsoft Sentinel to ingest Defender for Identity alerts.

Microsoft Defender for Identity sensors on domain controllers provide deep behavioral analytics and detect advanced on-premises AD DS attacks such as pass-the-hash and reconnaissance. Integrating Defender for Identity with Microsoft Sentinel enables centralized incident correlation and automated response. This combination directly satisfies the requirement for detecting on-premises threats and integrating with Sentinel for a comprehensive security operations solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy Microsoft Defender for Identity sensors on domain controllers and configure Microsoft Sentinel to ingest Defender for Identity alerts.

    Why this is correct

    This is correct because Microsoft Defender for Identity sensors installed on domain controllers monitor AD DS traffic and use behavioral analytics to detect advanced attacks like pass-the-hash and reconnaissance. Integrating with Microsoft Sentinel allows centralized incident correlation and response. This directly meets the requirement for detecting on-premises AD DS threats and integrating with Sentinel.

  • ✗

    Configure Microsoft Entra ID Protection risk policies and stream risk detections to Microsoft Sentinel.

    Why it's wrong here

    This is incorrect because Microsoft Entra ID Protection detects identity risks in Microsoft Entra ID, such as leaked credentials or atypical sign-ins, not on-premises Active Directory Domain Services attacks like pass-the-hash. It does not monitor domain controller traffic or provide the behavioral analytics needed for AD DS reconnaissance detection. This solution does not address the on-premises threat detection requirement.

  • ✗

    Enable Microsoft Defender for Cloud Apps anomaly detection policies and connect them to Microsoft Sentinel.

    Why it's wrong here

    This is incorrect because Microsoft Defender for Cloud Apps focuses on cloud app usage and anomaly detection, not on-premises Active Directory Domain Services attack detection. It cannot detect pass-the-hash or reconnaissance against domain controllers. While it can integrate with Sentinel, it does not provide the required behavioral analytics for on-premises AD DS threats described in the scenario.

  • ✗

    Install Microsoft Monitoring Agent on domain controllers and create custom log queries in Microsoft Sentinel to detect suspicious activity.

    Why it's wrong here

    This is incorrect because while Microsoft Monitoring Agent can collect logs, it does not provide the built-in behavioral analytics and specialized detection capabilities of Microsoft Defender for Identity. Custom queries would require significant effort to replicate Defender for Identity's advanced attack detection, and would not natively identify pass-the-hash or reconnaissance with the same fidelity. This approach is less effective and more administratively burdensome.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.