Answer – D
The Microsoft documentation states the below feature on the Microsoft Defender for Identity service.
Microsoft Defender for Identity is a cloud-based security solution that leverages your on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization.
<h2>Monitor and analyze user behavior and activities</h2>
Defender for Identity`s proprietary sensors monitor organizational domain controllers, providing a comprehensive view of all user activities from every device. Defender for Identity monitors and analyzes user activities and information across your network, such as permissions and group membership, creating a behavioral baseline for each user.
Options A and C are incorrect since these are used for protecting identities in Azure AD.
Option B is incorrect since this is solely a solution to protect against DDoS attacks.
For more information on Azure Advanced Threat Protection, please visit the below URL-
https://docs.microsoft.com/en-us/defender-for-identity/what-is