hardMultiple ChoiceObjective-mapped
220-1102 Practice Question: After a security incident, a forensic analyst…
After a security incident, a forensic analyst needs to review the event logs on a Windows 10 system to determine when a specific user account was created. The logs are intact. Which Windows security setting must be enabled to ensure that account creation events are recorded?
⚠ Common exam trap
Many exam-takers confuse 'Audit Logon Events' (which deals with authentication) with 'Audit Account Management' (which deals with account creation and modification), leading them to select the wrong policy for recording account creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable 'Audit Account Management' in Advanced Audit Policy.
User account creation is an account management event, not a logon event. In Windows 10, the 'Audit Account Management' policy under Advanced Audit Policy Configuration must be enabled to record Security Event ID 4720 (a user account was created). This setting logs all changes to user and group accounts, including creation, modification, and deletion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable 'Audit Logon Events' in Local Security Policy.
Why it's wrong here
Enabling 'Audit Logon Events' in Local Security Policy configures the system to log successful and failed user logon attempts, logoffs, and special logons. While crucial for monitoring access and identifying potential brute-force attacks or unauthorized access, this specific audit policy does not record events related to the creation, modification, or deletion of user accounts or security groups. Therefore, it would not provide the necessary forensic evidence for tracking when a new account was established after a security incident.
- ✓
Enable 'Audit Account Management' in Advanced Audit Policy.
Why this is correct
Enabling 'Audit Account Management' within the Advanced Audit Policy settings is the correct action because it specifically configures the operating system to log events related to user and group account management. This includes the creation, deletion, or modification of user accounts, security groups, and even password changes. For a forensic analyst investigating a security incident, these detailed logs are essential for identifying unauthorized account creation or privilege escalation, providing a clear audit trail of administrative changes.
- ✗
Turn on 'File and Printer Sharing' in Network and Sharing Center.
Why it's wrong here
Turning on 'File and Printer Sharing' in the Network and Sharing Center enables other computers on the network to access shared files and printers from the local machine. This is a network service configuration designed to facilitate resource sharing across a local area network (LAN) or homegroup. It has no direct or indirect impact on the system's event logging capabilities or the auditing of administrative actions like account creation, making it entirely irrelevant to a forensic investigation focused on account management events.
- ✗
Configure Windows Defender to scan for new accounts.
Why it's wrong here
Configuring Windows Defender to scan for new accounts is not a valid or effective action for logging account creation events. Windows Defender is primarily an anti-malware and antivirus solution that provides real-time protection against malicious software, spyware, and other threats. Its functionality does not extend to auditing or logging system-level administrative actions such as the creation of user accounts, nor does it possess a feature to 'scan' for new accounts in a forensic logging context. This task falls under the purview of Windows Audit Policy, not endpoint protection software.
Go deeper
Related to this question
Learn chapter
Windows Editions and Features
Key term
Event
An event is any identifiable occurrence or action in a computer system, network, or application that can be logged, monitored, or analyzed for security or operational purposes.
Key term
Windows 10
Windows 10 is a personal computer operating system developed by Microsoft that combines the familiarity of Windows 7 with the modern features of Windows 8, designed to run on a wide range of devices from desktops to tablets.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.