Quiz 3 Question 6 of 20

A SOC analyst investigates a suspected lateral movement incident involving a compromised service account. The analyst needs to correlate evidence of the attacker's initial access, persistence mechanism, and subsequent privilege escalation within the same time window. Which combination of Windows Event Log sources should the analyst query to capture these specific activities?

Select an answer to reveal the explanation.

Motivation