Your network contains an Active Directory domain named contoso.com. You are deploying
Microsoft Advanced Threat Analytics (ATA) to the domain. You install the ATA Center on server
named Server1 and the ATA Gateway on a server named Served. You need to ensure that Server2
can collect NTLM authentication events. What should you configure?
A.
the domain controllers to forward Event ID 4776 to Server2
B.
the domain controllers to forward Event ID 1000 to Server1
C.
Server2 to forward Event ID 1026 to Server1
D.
Server1 to forward Event ID 1000 to Server2