Containing a Defender for Identity pass-the-ticket alert by quarantining only the affected device
You have an on-premises network. You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Identity. From the Microsoft Defender portal, you investigate an incident on a device named Device1 of a user named User1. The incident contains the following Defender for Identity alert. Suspected identity theft (pass-the-ticket) (external ID 2018) You need to contain the incident without affecting users and devices. The solution must minimize administrative effort. What should you do?
Community Votes
54% of anonymous learners picked answer E. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
In a pass-the-ticket attack the stolen ticket is tied to the device, not the user credential, so isolating the device contains the incident without disabling accounts or resetting passwords, which is the minimal-effort, minimal-blast-radius response.
A Defender for Identity 'Suspected identity theft (pass-the-ticket)' alert on Device1 means a forged Kerberos ticket resides on that device; quarantining Device1 isolates the threat with the least disruption, while User1 can keep working elsewhere.
Disabling the user or resetting passwords as well — those actions disrupt User1 and other accounts and are not required to contain a device-resident ticket; they exceed the minimal-effort containment the question asks for.
Community Discussion (14 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A pass-the-ticket alert indicates an attacker reused a Kerberos ticket that lives on the compromised device (Device1), not a compromised user credential. The lowest-effort containment that limits blast radius is to quarantine/isolate Device1 from the network. User1's account remains usable on other devices, satisfying the 'without affecting users' intent and minimizing administrative effort.Why the Other Options Are Wrong
Disabling User1 (A) disrupts the user unnecessarily and does not remove the ticket from the device. Resetting passwords for all accounts on Device1 (C) is broad and disruptive. Combining disable + quarantine (D) or all three (E) exceeds the minimal-effort containment and affects more users and devices than needed.Community Comment Notes
This is heavily contested (E 44 vs B 38). Takakage, g_man_rap, Syncure, scfitzp, and Hawklx argue B, noting the ticket is device-resident and quarantine contains it with minimal impact. DChilds (11 likes) says their team does E, but E is more disruptive than the minimal-effort requirement. My determination follows the device-isolation reasoning.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →