ネットワークには、Domain1 という名前の Active Directory ドメイン サービス (AD DS) ドメインが含まれています。 Microsoft Entra テナントがあります。 Domain1 は、Microsoft Entra Connect を使用してテナントと同期します。 権限昇格攻撃について Domain1 を監視する必要があります。 何を使うべきでしょうか?
正解:C
Defender for Identity is fully integrated with Microsoft Defender XDR, and leverages signals from both on-premises Active Directory and cloud identities to help you better identify, detect, and investigate advanced threats directed at your organization. Note: Detecting and preventing privilege escalation attacks leveraging Kerberos relaying (KrbRelayUp) Microsoft Defender for Identity detects activity from the early stages of the attack chain by monitoring anomalous behavior as seen by the domain controller. Reference: https://learn.microsoft.com/en-us/defender-for-identity/what-is https://www.microsoft.com/en-us/security/blog/2022/05/25/detecting-and-preventing-privilege- escalation-attacks-leveraging-kerberos-relaying- krbrelayup/