Be able to run and read PowerShell auditing commands, set script-signing policy, interpret auditpol configuration output, and enable file access auditing correctly. The key is knowing that audit policy configuration and the SACL must both be set before Windows records file read or write events.
Start practicing
Windows Automation and Auditing — choose a session length
Free · No account required
Domain overview
This GSEC domain covers auditing and automating Windows hosts with native tooling. Questions present realistic scenarios: verifying local group membership and scheduled tasks, enforcing PowerShell script signing, reading audit policy output, and enabling object access auditing on file shares. Expect command-level answers using PowerShell, auditpol, and Group Policy rather than third-party products.
Exam objectives
Using PowerShell cmdlets such as Get-LocalGroupMember and Get-ScheduledTask to audit a host
Enforcing AllSigned execution policy via Set-ExecutionPolicy to require digitally signed scripts
Interpreting auditpol output to determine Account Logon audit configuration state
Enabling object access auditing through Group Policy or auditpol for file read/write events
Confusing execution policy scope: Set-ExecutionPolicy changes policy but is not a security boundary and can be bypassed.
Assuming auditpol shows events; it only configures policy, while Event Viewer or wevtutil surfaces the records.
Enabling object access auditing without configuring a SACL on the target file or folder, so no events are logged.
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are auditing a Windows server and need to identify which user accounts have recently utilized elevated privileges. Which specific Event ID should you prioritize in the Security log?
2Refer to the exhibit. What is the current configuration state for auditing 'Account Logon' events based on the provided output?
3Which TWO of the following PowerShell commands would you use to audit current local group membership and verify existing scheduled tasks on a compromised Windows server?
4You are hardening a Windows environment and must restrict the use of PowerShell to only digitally signed scripts. Which command should you execute?
5Which Windows component is responsible for the centralized management of security configurations, including password policies and user rights, across a domain?
6Which THREE of the following are considered best practices for auditing Windows event logs to enhance security monitoring?
7Which PowerShell command is used to display the current status of advanced auditing policies on a Windows system?
8You are a security analyst at a company that suspects an insider is exfiltrating files from a Windows Server 2019 file server. You need to enable auditing to record every time a file is read or written on a specific shared folder, while minimizing the volume of unrelated events. Which of the following should you do first?
9A security administrator needs to ensure that all Windows 10 workstations in a domain automatically forward their security event logs to a central collector to prevent tampering and enable correlation. The organization uses Group Policy. Which of the following should the administrator configure?
10You are a security analyst at a financial firm. A Windows Server 2019 domain controller is suspected of unauthorized access. You need to determine which user accounts were used to log on interactively to that server during the past week. Which Windows Event ID should you examine?
11You are a security administrator for a Windows environment. You need to audit changes to critical files on a file server to detect unauthorized modifications. You decide to use Windows auditing features. Which TWO of the following steps must you perform to enable and capture file modification events? (Choose two.)
12A security analyst at a financial firm suspects that an attacker used a service account to create a new local administrator on a Windows 10 workstation. The analyst runs `auditpol /get /category:*` and sees that the 'Account Management' subcategory is set to 'No Auditing'. Which action should the analyst take to capture future events of this type while minimizing noise?
13You are a security consultant reviewing a Windows Server 2016 environment. The client wants to ensure that all administrative actions are logged and can be traced back to individual administrators. Currently, all administrators use a shared domain admin account. Which security control should you recommend to meet this requirement?
14A junior administrator needs to quickly identify all Windows services that are currently set to start automatically but are not running on a Windows Server 2016. Which PowerShell command should the administrator use?
15A security administrator wants to enable PowerShell script block logging on a Windows 10 workstation to capture suspicious script content. The administrator runs `Get-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging'`. Which registry value should be configured to enable this feature?
16A security analyst at a financial institution is auditing a Windows Server 2019 domain controller. The organization's policy requires that all authentication attempts, including failed logons, be logged for forensic analysis. The analyst runs 'auditpol /get /category:*' and notices that the 'Logon/Logoff' category shows 'No Auditing'. Which command should the analyst use to enable auditing for both successful and failed logon events?
Be able to run and read PowerShell auditing commands, set script-signing policy, interpret auditpol configuration output, and enable file access auditing correctly. The key is knowing that audit policy configuration and the SACL must both be set before Windows records file read or write events.
The Courseiva GSEC question bank contains 16 questions in the Windows Automation and Auditing domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Windows Automation and Auditing domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included