nerdexam
Microsoft

SC-200 · Question #88

You have the following environment: - Azure Sentinel - A Microsoft 365 subscription - Microsoft Defender for Identity - An Azure Active Directory (Azure AD) tenant You configure Azure Sentinel to…

The correct answer is A. Configure the Advanced Audit Policy Configuration settings for the domain controllers. D. Configure Windows Event Forwarding on the domain controllers. For the correct events to be audited and included in the Windows Event Log, your domain controllers require accurate Advanced Audit Policy settings. To enhance detection capabilities, Defender for Identity needs the Windows events listed in Configure event collection. These can…

Submitted by yuki_2020· Apr 18, 2026Configure protections and detections

Question

You have the following environment:

  • Azure Sentinel
  • A Microsoft 365 subscription
  • Microsoft Defender for Identity
  • An Azure Active Directory (Azure AD) tenant

You configure Azure Sentinel to collect security logs from all the Active Directory member servers and domain controllers. You deploy Microsoft Defender for Identity by using standalone sensors. You need to ensure that you can detect when sensitive groups are modified in Active Directory. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AConfigure the Advanced Audit Policy Configuration settings for the domain controllers.
  • BModify the permissions of the Domain Controllers organizational unit (OU).
  • CConfigure auditing in the Microsoft 365 compliance center.
  • DConfigure Windows Event Forwarding on the domain controllers.

How the community answered

(28 responses)
  • A
    82% (23)
  • B
    11% (3)
  • C
    7% (2)

Explanation

For the correct events to be audited and included in the Windows Event Log, your domain controllers require accurate Advanced Audit Policy settings. To enhance detection capabilities, Defender for Identity needs the Windows events listed in Configure event collection. These can either be read automatically by the Defender for Identity sensor or in case the Defender for Identity sensor is not deployed, it can be forwarded to the Defender for Identity standalone sensor in one of two ways, by configuring the Defender for Identity standalone sensor to listen for SIEM events or by configuring Windows Event Forwarding. https://learn.microsoft.com/en-us/defender-for-identity/configure-windows-event-collection https://learn.microsoft.com/en-us/defender-for-identity/configure-event-forwarding

Topics

#Active Directory auditing#Defender for Identity#Log collection#Detection configuration

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice