SC-200 Exam QuestionsBrowse all questions from this exam

SC-200 Exam - Question 278


Your on-premises network contains an Active Directory Domain Services (AD DS) forest.

You have a Microsoft Entra tenant that uses Microsoft Defender for Identity. The AD DS forest syncs with the tenant.

You need to create a hunting query that will identify LDAP simple binds to the AD DS domain controllers.

Which table should you query?

Show Answer
Correct Answer:

Discussion

4 comments
Sign in to comment
DChildsOption: D
Apr 25, 2024

Here is a sample query from Microsoft Learn documentation: https://learn.microsoft.com/en-us/azure/azure-monitor/reference/queries/identitylogonevents

rsanx42
May 30, 2024

Agreed.

pk69Option: D
Apr 25, 2024

IdentityLogonEvents

laddu001Option: B
May 26, 2024

, the correct table to query for identifying LDAP simple binds to the AD DS domain controllers is AADDomainServicesAccountLogon.\

Hawklx
Jul 12, 2024

No, this is for Entra ID Domain Services

e072f83Option: D
Jun 12, 2024

https://techcommunity.microsoft.com/t5/security-compliance-and-identity/enhancing-microsoft-defender-for-identity-data-using-microsoft/ba-p/2178286