Quiz 10 Question 14 of 20

A security engineer is deploying a SIEM and needs to onboard Windows Domain Controller logs. Which Windows Security event category must be enabled via Group Policy to capture user account management events such as group membership changes?

Select an answer to reveal the explanation.

Motivation