ExamQuestions.com

Register
Login
Microsoft Security Operations Analyst (SC-200) Exam Questions

Microsoft

Microsoft Security Operations Analyst (SC-200)

51 / 130

Question 51:

You are currently using Azure Sentinel for the collection of Windows security events. You want to use Azure Sentinel to identify Remote Desktop Protocol (RDP) activity that is unusual for your environment. 
You need to enable the Anomalous RDP Login Detection rule. 
What two prerequisites do you need to ensure are in place before you can enable this rule? Each correct answer presents part of the solution. Choose the correct answers.

Answer options:

A.Collect Security events or Windows Security Events with Event ID 4624.
B.Select and event set other than None.
C.Let the machine learning algorithm collect 30 days’ worth of Windows Security events data.
D.Collect Security events or Windows Security Events with Event ID 4720.