Courseiva
mediumMultiple Choice

220-1202 Practice Question: After a security incident, a forensic analyst…

After a security incident, a forensic analyst needs to ensure that Windows 10 audit logs capture all successful and failed attempts to access the 'Confidential' folder on a file server. Which audit policy configuration is required?

⚠ Common exam trap

CompTIA often tests the misconception that enabling 'Audit object access' alone is sufficient, but candidates forget that a SACL must also be explicitly configured on the target object for any audit events to be generated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable 'Audit object access' and configure the SACL on the folder

To audit access attempts to a specific folder, you must enable the 'Audit object access' policy in the Advanced Audit Policy Configuration (or the legacy 'Audit object access' under Local Policies). This policy alone does not audit anything; you must also configure a System Access Control List (SACL) on the 'Confidential' folder itself, specifying which access types (e.g., Read, Write) for which users or groups to audit for success and failure. Without the SACL, no object access events are generated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 'Audit account logon events' for success and failure

    Why it's wrong here

    Account logon events record authentication to a domain controller or local account, not object access on a file server. It would be correct when auditing Kerberos or NTLM authentication success and failure, not folder reads.

  • ✓

    Enable 'Audit object access' and configure the SACL on the folder

    Why this is correct

    Object access auditing requires two elements: the Audit object access policy enabled in Group Policy or Local Security Policy, and a system access control list (SACL) set on the folder itself specifying success and failure events. Both together capture the required access attempts.

  • ✗

    Enable 'Audit privilege use' for success and failure

    Why it's wrong here

    Privilege use auditing records exercise of user rights such as backup or debug, not file or folder access. It would be the correct choice when tracking who invoked sensitive privileges, not when capturing reads of a specific folder.

  • ✗

    Enable 'Audit process tracking' for success and failure

    Why it's wrong here

    Process tracking logs process creation, exit and handle duplication, not file or folder access. It would be the correct choice when investigating which executables ran or how processes interacted, not when capturing reads of the Confidential folder.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.