Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security operations team is investigating a series of suspicious activities involving a high-privilege service account. They suspect that the account's credentials might have been compromised and are being used to enumerate domain controllers and access sensitive shares. Which Microsoft Defender for Identity sensor type is primarily responsible for monitoring traffic directly from domain controllers to detect such activities?

  1. AAzure Active Directory Connect sensor
  2. BStandalone sensor
  3. CNetwork appliance sensor
  4. DIntegrated sensor on domain controller
Show answer & explanation

Correct answer: D. Integrated sensor on domain controller

Microsoft Defender for Identity sensors installed directly on domain controllers capture network traffic and Windows events, which are essential for detecting enumeration activities and access to sensitive resources originating from or targeting domain controllers.

Why the other options are wrong

  • A. The Azure Active Directory Connect sensor monitors synchronization activities and related events, not general network traffic or sensitive share access on domain controllers.
  • B. A standalone sensor monitors port-mirrored traffic from other network devices, not directly from the DC itself.
  • C. A network appliance sensor is a generic term and not a specific Microsoft Defender for Identity sensor type; it could refer to a standalone sensor, but 'integrated' is more precise for direct DC monitoring.

Defender for Identity Sensor Types

Microsoft Defender for Identity uses sensors to collect data from domain controllers and network traffic to detect threats.

  • Integrated sensors run directly on domain controllers.
  • Standalone sensors run on dedicated servers, monitoring port-mirrored traffic.
  • Sensor placement dictates visibility into specific threat vectors.

Memory trick: Integrated sensors live inside the brain (DC), standalone sensors watch from afar.

More Mitigate threats using Microsoft Defender XDR questions