ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 56 - SC-200 discussion

Report
Export

You have the following environment:

Azure Sentinel

A Microsoft 365 subscription

Microsoft Defender for Identity

An Azure Active Directory (Azure AD) tenant

You configure Azure Sentinel to collect security logs from all the Active Directory member servers and domain controllers.

You deploy Microsoft Defender for Identity by using standalone sensors.

You need to ensure that you can detect when sensitive groups are modified in Active Directory.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

Configure the Advanced Audit Policy Configuration settings for the domain controllers.

Answers
A.

Configure the Advanced Audit Policy Configuration settings for the domain controllers.

B.

Modify the permissions of the Domain Controllers organizational unit (OU).

Answers
B.

Modify the permissions of the Domain Controllers organizational unit (OU).

C.

Configure auditing in the Microsoft 365 compliance center.

Answers
C.

Configure auditing in the Microsoft 365 compliance center.

D.

Configure Windows Event Forwarding on the domain controllers.

Answers
D.

Configure Windows Event Forwarding on the domain controllers.

Suggested answer: A, D

Explanation:

Reference:

https://docs.microsoft.com/en-us/defender-for-identity/configure-windows-event-collection

https://docs.microsoft.com/en-us/defender-for-identity/configure-event-collection

asked 05/10/2024
Kaisheng Wang
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first