mediumMultiple Choice
220-1202 Practice Question: After a security incident, a forensic analyst…
After a security incident, a forensic analyst needs to ensure that Windows 10 audit logs capture all successful and failed attempts to access the 'Confidential' folder on a file server. Which audit policy configuration is required?
⚠ Common exam trap
CompTIA often tests the misconception that enabling 'Audit object access' alone is sufficient, but candidates forget that a SACL must also be explicitly configured on the target object for any audit events to be generated.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable 'Audit object access' and configure the SACL on the folder
To audit access attempts to a specific folder, you must enable the 'Audit object access' policy in the Advanced Audit Policy Configuration (or the legacy 'Audit object access' under Local Policies). This policy alone does not audit anything; you must also configure a System Access Control List (SACL) on the 'Confidential' folder itself, specifying which access types (e.g., Read, Write) for which users or groups to audit for success and failure. Without the SACL, no object access events are generated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable 'Audit account logon events' for success and failure
Why it's wrong here
Account logon events record authentication to a domain controller or local account, not object access on a file server. It would be correct when auditing Kerberos or NTLM authentication success and failure, not folder reads.
- ✓
Enable 'Audit object access' and configure the SACL on the folder
Why this is correct
Object access auditing requires two elements: the Audit object access policy enabled in Group Policy or Local Security Policy, and a system access control list (SACL) set on the folder itself specifying success and failure events. Both together capture the required access attempts.
- ✗
Enable 'Audit privilege use' for success and failure
Why it's wrong here
Privilege use auditing records exercise of user rights such as backup or debug, not file or folder access. It would be the correct choice when tracking who invoked sensitive privileges, not when capturing reads of a specific folder.
- ✗
Enable 'Audit process tracking' for success and failure
Why it's wrong here
Process tracking logs process creation, exit and handle duplication, not file or folder access. It would be the correct choice when investigating which executables ran or how processes interacted, not when capturing reads of the Confidential folder.
Visual reference
Go deeper
Related to this question
About these practice questions
This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.