Courseiva
hardMultiple Choice

220-1102 Practice Question: During a security audit, you need to identify all…

During a security audit, you need to identify all user accounts that have been created or modified in the last 24 hours on a Windows Server. Which command-line tool can parse security event logs to extract this information?

⚠ Common exam trap

CompTIA exams often test the distinction between graphical tools (eventvwr) and command-line tools (wevtutil), and candidates may confuse 'net user' as a log-parsing tool when it only shows current account state, not historical changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

wevtutil qe Security /q:"*[System[TimeCreated[timediff(@SystemTime) <= 86400000]]]"

The wevtutil command with the 'qe' (query-events) parameter and an XPath filter can directly query the Security event log for events created within a specific time window. The filter '*[System[TimeCreated[timediff(@SystemTime) <= 86400000]]]' retrieves events whose creation time is within the last 86,400,000 milliseconds (24 hours), allowing you to identify user accounts created or modified via event IDs such as 4720 (user created) or 4738 (user changed).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    wevtutil qe Security /q:"*[System[TimeCreated[timediff(@SystemTime) <= 86400000]]]"

    Why this is correct

    wevtutil's query flag parses the Security log using XPath, and the timediff filter compares each event's TimeCreated against the current system time in milliseconds, so 86400000 restricts results to the last 24 hours. This directly satisfies the audit's requirement to extract recently created or modified accounts.

  • ✗

    eventvwr

    Why it's wrong here

    Eventvwr opens the graphical Event Viewer console, not a command-line parser producing filtered output for scripting. Wevtutil queries and exports security logs from the command line. Eventvwr is tempting because it displays the same Security log interactively, but it would be the right tool for manual visual inspection rather than automated extraction.

  • ✗

    net user

    Why it's wrong here

    Net user manages local accounts and displays account properties, but it does not read or parse security event logs, so creation and modification timestamps are unavailable. Wevtutil queries those logs. Net user is tempting because it lists accounts, but it would be correct only for enumerating or modifying accounts directly, not auditing event history.

  • ✗

    diskpart

    Why it's wrong here

    Diskpart manages disks, partitions and volumes; it has no access to security event logs or user account records. Wevtutil parses the Security log for account creation and modification events. Diskpart is tempting because it is a familiar command-line administrative tool, but it would be correct only for storage configuration tasks.

About these practice questions

This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.