I feel pretty confident about this one. The question is clearly focused on the display of the user ID, so the number of DETs should be based on that function. I'll go with option A.
Hmm, I'm a bit unsure about IoC Type and Cyber Kill Chain Step. Are those also considered baseline classifications? I'll have to think this through carefully.
Okay, I think I've got this. The key is to use the Microsoft Monitoring Agent on the VM to send the event log data to an Azure storage account, and then configure the alert in Azure Monitor to look for the specific event pattern. The SAS is just to give the agent access to the storage account. I feel pretty confident about this approach.
upvoted 0
times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Annamaria
10 months agoFelicidad
10 months agoBroderick
10 months agoCristen
10 months agoFrederica
11 months agoMagnolia
11 months agoValentine
11 months agoAlton
11 months agoAlonso
11 months agoMartina
11 months agoElvis
11 months agoHana
11 months agoMelina
11 months ago