List of questions
Related questions
Question 122 - SC-100 discussion
You have an Azure AD tenant that syncs with an Active Directory Domain Services {AD DS) domain.
Client computers run Windows and are hybrid-joined to Azure AD.
You are designing a strategy to protect endpoints against ransomware. The strategy follows Microsoft Security Best Practices. You plan to remove all the domain accounts from the Administrators group on the Windows computers.
You need to recommend a solution that will provide users with administrative access to the Windows computers only when access is required. The solution must minimize the lateral movement of ransomware attacks if an administrator account on a computer is compromised.
What should you include in the recommendation?
Local Administrator Password Solution (LAPS)
Privileged Access Workstations (PAWs)
Azure AD Privileged Identity Management (PIM)
Azure AD identity Protection
0 comments
Leave a comment first