20+ practice questions focused on Windows Automation and Auditing — one of the most tested topics on the GIAC Security Essentials exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Windows Automation and Auditing PracticeAn administrator needs to enforce password complexity across 500 domain-joined Windows workstations without using Group Policy Objects. Which tool is the most efficient choice for this task?
Explanation: Local Security Policy settings via PowerShell's 'net accounts' or 'secedit' can be automated via scripts to enforce complexity requirements on local databases. While GPO is preferred for enterprise management, script-based automation provides a direct configuration path when the domain infrastructure is unavailable or when managing workgroup computers. This ensures consistent security posture across heterogeneous environments where centralized policy management is restricted or impossible to implement effectively.
A security analyst needs to quickly identify all Windows services that are configured to start automatically on a Windows 10 workstation. Which PowerShell command should be used?
Explanation: The correct command uses Get-CimInstance to query Win32_Service and filters on the StartMode property equal to 'Auto'. This directly returns only services configured to start automatically. The other commands either fail due to invalid parameters or do not filter, so they do not efficiently answer the scenario.
A security consultant is reviewing the PowerShell execution policy on a Windows Server 2019 used for administrative tasks. The consultant runs `Get-ExecutionPolicy -List` and observes that the MachinePolicy scope is set to AllSigned. Which two statements accurately describe the behavior of PowerShell under this configuration? (Choose two.)
Explanation: The AllSigned execution policy requires all scripts and configuration files to be digitally signed by a trusted publisher. When set at the MachinePolicy scope, it cannot be overridden by local settings. Interactive commands are not restricted, and certificate expiration is validated at runtime unless timestamped. These two correct statements reflect key behaviors of AllSigned under Group Policy control.
A security analyst is investigating a suspected breach on a Windows Server 2019. The analyst runs the command `wevtutil qe Security /q:"*[System[(EventID=1102)]]" /f:text` and finds no results. What does this indicate about the security log?
Explanation: Event ID 1102 indicates the audit log was cleared. If a query for this event returns no results, it means the event is not present in the current log. Since the log retains events until it is cleared or overwritten, the absence suggests the log has not been cleared since auditing was enabled. Other interpretations require additional assumptions not supported by the scenario.
A security analyst is investigating a potential compromise on a Windows Server 2019 domain controller. The analyst wants to identify all accounts that were used to perform privileged operations, such as modifying domain admin group membership, within the last 24 hours. Which Windows Security event log source and event ID should the analyst focus on?
Explanation: Event ID 4728 is logged when a member is added to a security-enabled global group, which includes privileged groups like Domain Admins. This event captures both the actor and the target, making it ideal for identifying accounts that performed privileged operations. Other events like 4672 or 4624 do not record group membership changes.
+15 more Windows Automation and Auditing questions available
Practice all Windows Automation and Auditing questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Windows Automation and Auditing. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Windows Automation and Auditing questions on the GSEC frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Windows Automation and Auditing is tested as part of the GIAC Security Essentials blueprint. Practicing with targeted Windows Automation and Auditing questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GSEC practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Windows Automation and Auditing is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Windows Automation and Auditing practice session with instant scoring and detailed explanations.
Start Windows Automation and Auditing Practice →