Courseiva
hardMultiple ChoiceObjective-mapped

220-1102 Practice Question: After a security incident, a forensic analyst…

After a security incident, a forensic analyst needs to review the event logs on a Windows 10 system to determine when a specific user account was created. The logs are intact. Which Windows security setting must be enabled to ensure that account creation events are recorded?

⚠ Common exam trap

Many exam-takers confuse 'Audit Logon Events' (which deals with authentication) with 'Audit Account Management' (which deals with account creation and modification), leading them to select the wrong policy for recording account creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable 'Audit Account Management' in Advanced Audit Policy.

User account creation is an account management event, not a logon event. In Windows 10, the 'Audit Account Management' policy under Advanced Audit Policy Configuration must be enabled to record Security Event ID 4720 (a user account was created). This setting logs all changes to user and group accounts, including creation, modification, and deletion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable 'Audit Logon Events' in Local Security Policy.

    Why it's wrong here

    Enabling 'Audit Logon Events' in Local Security Policy configures the system to log successful and failed user logon attempts, logoffs, and special logons. While crucial for monitoring access and identifying potential brute-force attacks or unauthorized access, this specific audit policy does not record events related to the creation, modification, or deletion of user accounts or security groups. Therefore, it would not provide the necessary forensic evidence for tracking when a new account was established after a security incident.

  • Enable 'Audit Account Management' in Advanced Audit Policy.

    Why this is correct

    Enabling 'Audit Account Management' within the Advanced Audit Policy settings is the correct action because it specifically configures the operating system to log events related to user and group account management. This includes the creation, deletion, or modification of user accounts, security groups, and even password changes. For a forensic analyst investigating a security incident, these detailed logs are essential for identifying unauthorized account creation or privilege escalation, providing a clear audit trail of administrative changes.

  • Turn on 'File and Printer Sharing' in Network and Sharing Center.

    Why it's wrong here

    Turning on 'File and Printer Sharing' in the Network and Sharing Center enables other computers on the network to access shared files and printers from the local machine. This is a network service configuration designed to facilitate resource sharing across a local area network (LAN) or homegroup. It has no direct or indirect impact on the system's event logging capabilities or the auditing of administrative actions like account creation, making it entirely irrelevant to a forensic investigation focused on account management events.

  • Configure Windows Defender to scan for new accounts.

    Why it's wrong here

    Configuring Windows Defender to scan for new accounts is not a valid or effective action for logging account creation events. Windows Defender is primarily an anti-malware and antivirus solution that provides real-time protection against malicious software, spyware, and other threats. Its functionality does not extend to auditing or logging system-level administrative actions such as the creation of user accounts, nor does it possess a feature to 'scan' for new accounts in a forensic logging context. This task falls under the purview of Windows Audit Policy, not endpoint protection software.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.