SC-200 · Question #88
You have the following environment: - Azure Sentinel - A Microsoft 365 subscription - Microsoft Defender for Identity - An Azure Active Directory (Azure AD) tenant You configure Azure Sentinel to…
The correct answer is A. Configure the Advanced Audit Policy Configuration settings for the domain controllers. D. Configure Windows Event Forwarding on the domain controllers. For the correct events to be audited and included in the Windows Event Log, your domain controllers require accurate Advanced Audit Policy settings. To enhance detection capabilities, Defender for Identity needs the Windows events listed in Configure event collection. These can…
Question
You have the following environment:
- Azure Sentinel
- A Microsoft 365 subscription
- Microsoft Defender for Identity
- An Azure Active Directory (Azure AD) tenant
You configure Azure Sentinel to collect security logs from all the Active Directory member servers and domain controllers. You deploy Microsoft Defender for Identity by using standalone sensors. You need to ensure that you can detect when sensitive groups are modified in Active Directory. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Options
- AConfigure the Advanced Audit Policy Configuration settings for the domain controllers.
- BModify the permissions of the Domain Controllers organizational unit (OU).
- CConfigure auditing in the Microsoft 365 compliance center.
- DConfigure Windows Event Forwarding on the domain controllers.
How the community answered
(28 responses)- A82% (23)
- B11% (3)
- C7% (2)
Explanation
For the correct events to be audited and included in the Windows Event Log, your domain controllers require accurate Advanced Audit Policy settings. To enhance detection capabilities, Defender for Identity needs the Windows events listed in Configure event collection. These can either be read automatically by the Defender for Identity sensor or in case the Defender for Identity sensor is not deployed, it can be forwarded to the Defender for Identity standalone sensor in one of two ways, by configuring the Defender for Identity standalone sensor to listen for SIEM events or by configuring Windows Event Forwarding. https://learn.microsoft.com/en-us/defender-for-identity/configure-windows-event-collection https://learn.microsoft.com/en-us/defender-for-identity/configure-event-forwarding
Topics
Community Discussion
No community discussion yet for this question.