SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Identity. You need to receive alerts when suspicious LDAP queries are detected. What should you configure?
⚠ Common exam trap
It's easy for candidates to confuse Microsoft Defender for Cloud Apps' anomaly detection policies with MDI's alert rules, not realizing that LDAP query monitoring is a core MDI function tied to on-premises Active Directory traffic, not cloud app behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure alert rules in Microsoft Defender for Identity.
Microsoft Defender for Identity (MDI) detects suspicious LDAP queries, such as LDAP reconnaissance or directory traversal attacks, by analyzing domain controller traffic. To receive alerts for these detections, you must configure alert rules directly within the MDI portal, which allows you to set thresholds and notification preferences for specific LDAP-related activities. Option B is correct because MDI's built-in alert rules are the mechanism for generating and delivering these security alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set up an anomaly detection policy in Microsoft Defender for Cloud Apps.
Why it's wrong here
Anomaly detection policies in Microsoft Defender for Cloud Apps, a cloud access security broker (CASB), analyze user behavior across SaaS applications to flag activities such as impossible travel, mass file download, or risky sign-ins. These policies do not inspect on-premises LDAP protocol traffic because LDAP queries are sent directly to domain controllers, which is precisely the telemetry collected by Microsoft Defender for Identity's domain controller sensors. As a result, setting up an anomaly detection policy there would not generate any alert about suspicious LDAP reconnaissance.
- ✓
Configure alert rules in Microsoft Defender for Identity.
Why this is correct
Defender for Identity's alert rules are the correct mechanism to detect suspicious LDAP queries because its lightweight sensor, installed on domain controllers, AD FS, and AD CS servers, monitors incoming LDAP traffic. The service includes a built-in alert rule named "LDAP reconnaissance" that compares query patterns to known reconnaissance techniques such as account enumeration, group membership queries, or unauthenticated LDAP searches. By configuring this alert rule—adjusting thresholds and enabling it to trigger—you directly satisfy the requirement to detect suspicious LDAP queries.
- ✗
Assign the Security Administrator role in Microsoft Entra ID.
Why it's wrong here
Assigning the Security Administrator role in Microsoft Entra ID grants a user administrative permissions to manage identity and access, such as configuring conditional access policies or reviewing security reports, but it does not itself enable any detection mechanism. Role assignment is purely an authorization action; it does not create or activate alert rules in any security tool. To actually detect suspicious LDAP queries, you must go to Defender for Identity and configure its alert rules—granting a role alone is insufficient because no detection logic is invoked merely by assigning access.
- ✗
Create a custom sensitivity label in Microsoft Purview.
Why it's wrong here
Custom sensitivity labels in Microsoft Purview are used for data classification and protection, applying metadata such as encryption, rights management, or visual markings to files and emails across services like SharePoint, OneDrive, and Exchange Online. These labels have no connection to on-premises Active Directory authentication flows or LDAP protocol monitoring, so they cannot identify or alert on suspicious LDAP query patterns. Creating a sensitivity label is a data governance measure, completely unrelated to identity threat detection for LDAP-based reconnaissance.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.