Suspicious RDP connections have been observed on a host within your environment. How do you utilize Event Search to show all connections on this specific host?
A.
event_simpleName=UserIdentity LogonType_decimal=10 | table timestamp ComputerName UserName UserPrincipal LogonServer
B.
Table timestamp ComputerName UserName UserPrincipal LogonServer
C.
UserIdentity=LogonType_decimal=10 | table timestamp UserPrincipal LogonServer
D
Question as "specific host", so it need to search with the agent ID, so it is D
D. aid=[my-aid] event_simpleName=UserIdentity LogonType_decimal=10 | table timestamp
ComputerName UserName UserPrincipal LogonServer
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
alanalanalan
3 months, 4 weeks ago