Windows Event Logging Mini Module

I am having some difficulty connecting the dots in this module. Can someone give a clear & concise explanation on how we start analysing an Event ID 4624 and somehow end up moving to Event ID 4907? I don’t understand the progression. What information on Event ID 4624 led us to Event ID 4907? I would think it would be by filtering on the logon ID you got from 4624 but you can’t filter by logon ID.

Delving into the log details progressively reveals a narrative. For instance, the analysis begins with Event ID 4907, which signifies an audit policy change.