Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A company uses Microsoft Defender for Identity to protect its on-premises Active Directory environment. The security team has received an alert indicating a 'Suspicious service creation' on a domain controller. Upon investigation, they discover that a new service was created with highly privileged permissions by an account that typically only performs user management tasks. What is the MOST effective immediate action the security team should take using Defender for Identity capabilities?

  1. ABlock the IP address of the source workstation.
  2. BDisable the compromised user account in Active Directory.
  3. CInitiate a full endpoint scan on the domain controller.
  4. DIsolate the domain controller from the network.
Show answer & explanation

Correct answer: B. Disable the compromised user account in Active Directory.

Given the 'Suspicious service creation' by an 'account that typically only performs user management tasks' on a domain controller, disabling the compromised user account in Active Directory is the most effective immediate action to prevent further malicious activity using that identity.

Why the other options are wrong

  • A. Blocking an IP might be a secondary action, but the primary compromise is the identity, which could move to other IPs.
  • C. Initiating an endpoint scan is a good forensic step but does not immediately stop the ongoing misuse of a compromised identity.
  • D. Isolating the domain controller is a drastic measure that impacts critical services; it's typically a last resort after confirming severe compromise, and not the immediate action for an identity-based alert.

Defender for Identity Remediation

Actions taken within or in conjunction with Microsoft Defender for Identity to mitigate identity-based threats, often focusing on isolating or disabling compromised accounts.

  • Focuses on Active Directory accounts.
  • Aims to prevent lateral movement and privilege escalation.
  • Integrates with other Defender products for coordinated response.

Memory trick: When an identity is compromised, cut off its power source first.

More Mitigate threats using Microsoft Defender XDR questions