Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You are configuring Microsoft Defender for Identity to protect against lateral movement attacks. Which configuration should you prioritize to detect pass-the-hash attacks?

⚠ Common exam trap

Watch out — candidates often confuse prerequisites (port mirroring) or supporting features (SAM-R for lateral movement paths, WEF for event collection) with the specific configuration needed to detect pass-the-hash, which is the direct capture of NTLM hashes from network traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable 'Capture NTLM hashes' in the Microsoft Defender for Identity sensor configuration

Enabling 'Capture NTLM hashes' in the Microsoft Defender for Identity sensor configuration allows the sensor to extract NTLM hashes from network traffic. Pass-the-hash attacks rely on capturing and reusing NTLM hashes to authenticate laterally; by capturing these hashes, Defender for Identity can detect anomalies such as a hash being used from a different source or for suspicious logon attempts, directly identifying the attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure port mirroring for domain controllers

    Why it's wrong here

    Port mirroring duplicates network traffic to a monitoring interface, but Microsoft Defender for Identity sensors already receive network traffic through their own network adapter. While packet capture can reveal NTLM authentication attempts, it does not specifically enable the sensor to extract and analyze NTLM hashes from that traffic. Moreover, port mirroring is a switch-level configuration, not a sensor configuration setting, so it does not align with the scenario. For pass-the-hash detection, the sensor must be configured to capture NTLM hashes directly.

  • ✗

    Enable 'SAM-R' (Remote SAM) in the Microsoft Defender for Identity sensor configuration

    Why it's wrong here

    Enabling SAM-R (Remote SAM) in the Microsoft Defender for Identity sensor configuration queries remote machines to enumerate local administrator accounts, which is used to map lateral movement paths and determine which accounts have admin access. This setting does not capture NTLM hashes from network authentication traffic, nor does it detect the reuse of a hash in a pass-the-hash attack. While SAM-R improves visibility into privilege relationships, it is not the mechanism that identifies hash reuse during authentication.

  • ✗

    Configure Windows Event Forwarding (WEF) for domain controllers

    Why it's wrong here

    Windows Event Forwarding (WEF) can centralize domain controller security events, such as logon type 3 events, but it is an external data collection mechanism rather than a native Microsoft Defender for Identity sensor configuration. WEF relies on the event log content, and NTLM hashes are not present in standard Windows security events; therefore, WEF alone will not provide the hash capture required to detect pass-the-hash. The Defender for Identity sensor can locally collect these events without requiring WEF, and the key is enabling the sensor's NTLM hash capture feature to directly inspect authentication traffic.

  • ✓

    Enable 'Capture NTLM hashes' in the Microsoft Defender for Identity sensor configuration

    Why this is correct

    Enabling the 'Capture NTLM hashes' setting in the Microsoft Defender for Identity sensor configuration instructs the sensor to intercept NTLM authentication traffic on the network and extract the NTLM hashes used during the handshake. This is the foundational telemetry for pass-the-hash detection because the sensor can then correlate these captured hashes against account logon events to identify when a hash is reused from a different source. Without this setting, the sensor lacks the specific data needed to trigger pass-the-hash alerts, making it the correct configuration for this scenario.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.