Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your company uses Microsoft Defender for Identity to monitor on-premises Active Directory. You receive an alert about a potential lateral movement attack involving a service account. The alert indicates that the account was used to log in to multiple servers from a non-domain-joined machine. You need to investigate the alert and determine if the account is compromised. What should you do first?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the account’s activity timeline in Microsoft Defender for Identity to see all logins and accessed resources.

The correct first step because Microsoft Defender for Identity provides an activity timeline for each account, allowing you to review all logins, resources accessed, and other suspicious activities. This helps determine if the account is compromised before taking any action. Option A is incorrect because the account may be a member of privileged groups, but that alone does not confirm compromise; the activity timeline provides more context. Option B is incorrect because immediately resetting the password could disrupt legitimate operations and destroy evidence. Option D is incorrect because the user of a service account is typically not a person, and lateral movement alerts indicate automated or unauthorized behavior, so contacting a user is not appropriate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check if the account is a member of any privileged groups.

    Why it's wrong here

    Group membership shows potential blast radius but does not establish whether this service account's logins were malicious, so it cannot confirm compromise. Tempting because privileged-group review is standard triage for suspicious accounts, yet here the decisive evidence is the logon pattern itself, which the investigation should examine first.

  • ✗

    Immediately reset the service account password.

    Why it's wrong here

    Resetting the password destroys the evidence needed to determine whether the account is compromised and may disrupt legitimate services before the alert is validated. Tempting because containment is the instinctive response to suspected lateral movement, but remediation follows confirmation; the first step is investigating the reported logon activity.

  • ✓

    Review the account’s activity timeline in Microsoft Defender for Identity to see all logins and accessed resources.

    Why this is correct

    Reviewing the account's activity timeline in Microsoft Defender for Identity surfaces every login and accessed resource tied to the service account, directly addressing the lateral movement alert. This satisfies the need to establish whether the account was used across multiple servers from a non-domain-joined machine, confirming compromise before remediation.

  • ✗

    Contact the user to verify if they performed the logins.

    Why it's wrong here

    A service account is not interactive, so no user performed these logins and contacting one yields nothing. Tempting because verifying activity with a user is routine for suspicious sign-ins, but service accounts run automated processes; the investigation should examine the logon pattern and source machines instead.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.