SC-200 Respond to security incidents • Set 18
SC-200 Respond to security incidents Practice Test 18 — 15 questions with explanations. Free, no signup.
During an incident investigation, you find that a compromised account was used to log into a virtual machine via RDP from an IP address in a sanctioned country. The VM has Microsoft Defender for Endpoint installed. Which data source in Microsoft Sentinel would you query to see the RDP connection events?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.