Câu 37: SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads
You have Microsoft Security Copilot agents that authenticate by using Microsoft Entra service principals. You receive a Microsoft Defender alert triggered by the anomalous OAuth authentication of an agent's Microsoft Entra service principal. You need to assess the impact of the agent identity and identify which resour…
Nội dung câu hỏi
You have Microsoft Security Copilot agents that authenticate by using Microsoft Entra service principals. You receive a Microsoft Defender alert triggered by the anomalous OAuth authentication of an agent's Microsoft Entra service principal. You need to assess the impact of the agent identity and identify which resources are affected if the identity is abused for lateral movement. The solution must minimize administrative effort. What should you do?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. From Advanced hunting, create a query against the IdentityLogonEvents table to list all the sign-ins performed by the identity.
- B. From Attack paths, select the identity and view the blast radius. — đáp án hiện tại
- C. From AI Observability in Microsoft Purview Data Security Posture Management (DSPM), review the agent activity.
- D. From Microsoft Purview Audit, query the audit logs for all the role assignments granted to the identity.
- E. From Incidents, review incidents related to OAuth events reported by Microsoft Defender for Cloud Apps.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.