Quiz 14 Question 6 of 20

A SIEM is ingesting Windows Security event logs. An analyst wants to detect when an account is added to a privileged group such as Domain Admins. Which Windows Event ID should trigger the detection rule?

Select an answer to reveal the explanation.

Motivation