Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Identity. You need to monitor for potential lateral movement attacks using pass-the-hash techniques. Which entity type in Microsoft Defender for Identity should you focus on in the security alert timeline?

⚠ Common exam trap

Many candidates choose 'Device' or 'Computer' because they think lateral movement is about moving between machines, but Microsoft explicitly tracks the stolen credential (account) as the primary entity in PtH alerts, since the attack follows the user identity, not the hardware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Account

In Microsoft Defender for Identity, lateral movement attacks using pass-the-hash (PtH) techniques are tracked at the account entity level because the attacker reuses a stolen NTLM hash to authenticate as a specific user account across multiple devices. The security alert timeline groups related activities by the compromised account, enabling analysts to trace the attacker's steps from the initial breach to subsequent resource access. Focusing on the account entity provides the clearest view of the authentication attempts and successful logons that indicate PtH behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IP address

    Why it's wrong here

    In Defender for Identity pass-the-hash alerts, the IP address appears in the observed authentication events as either the source or destination endpoint of the NTLM replay. However, an IP address is simply contextual evidence that identifies the network route and can be shared or NATed, making it an unreliable primary entity. The alert's main entity is the account whose hash was stolen and reused, not the IP address.

  • ✓

    Account

    Why this is correct

    This is the correct answer because Defender for Identity's pass-the-hash detection is specifically designed to identify the identity (user account) whose NTLM hash was captured and then replayed to authenticate to another machine. The alert entry shows the compromised account as the primary entity, with supporting details such as the source and destination computers, protocols, and timestamps. The investigation should focus on resetting that account's credentials and hunting for other activities performed by it, since the account itself is the root of the lateral movement.

  • ✗

    Device

    Why it's wrong here

    While devices are inherently involved in pass-the-hash attacks, Defender for Identity treats them as peripheral entities rather than the alert's focus. The alert records the source device where the hash was originally used and the destination device against which it was replayed, but these endpoints simply provide context for where the attack occurred. The actual alert entity is the account that performed the series of logons, because the same hash being used from multiple devices indicates the account's credentials are compromised.

  • ✗

    Computer

    Why it's wrong here

    In a pass-the-hash alert, the 'Computer' field typically shows the hostname of a Windows machine involved in the attack chain, either where the attacker initially obtained the hash or where they later applied it. This is distinct from the user account entity because pass-the-hash exploits the NTLM authentication process, not a vulnerability in the computer itself. The alert is raised against the account, since replaying its hash across computers demonstrates that the identity's credentials are in the attacker's hands, making the computer merely an artifact in the evidence.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.