Courseiva

GSEC Windows Automation and Auditing Practice Question

A security administrator needs to ensure that all Windows 10 workstations in a domain automatically forward their security event logs to a central collector to prevent tampering and enable correlation. The organization uses Group Policy. Which of the following should the administrator configure?

⚠ Common exam trap

The trap here is assuming that increasing local log size or copying log files manually achieves centralization, when the exam expects knowledge of the built-in Windows Event Forwarding feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable "Windows Event Forwarding" via the Group Policy setting "Configure target Subscription Manager" under Computer Configuration > Administrative Templates > Windows Components > Event Forwarding.

Windows Event Forwarding (WEF) is the native mechanism for collecting events from multiple computers. The Group Policy setting "Configure target Subscription Manager" tells source computers where to send events. The collector then uses subscriptions to filter and store events. This approach is scalable, secure, and supports real-time forwarding. It also allows the collector to use a dedicated service account and can be configured to use HTTPS for encryption, preventing tampering and enabling centralized analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable the "Audit: Force audit policy subcategory settings" policy and set the Security log to archive when full.

    Why it's wrong here

    Forcing audit policy subcategory settings ensures advanced audit policies override basic ones, but it does not forward events. Archiving the log when full automatically saves the log before overwriting, but this is a local retention feature, not a forwarding solution. Neither setting addresses the requirement for centralized collection and tamper resistance across the domain.

  • ✗

    Deploy a custom PowerShell script via Group Policy that runs at startup to copy the Security.evtx file to a network share.

    Why it's wrong here

    Copying the entire Security.evtx file periodically is inefficient and can miss events between copies. It also requires the share to be writable by all workstations, introducing security risks. This method lacks real-time forwarding and does not use the built-in Windows Event Forwarding mechanism, making it less reliable and harder to manage at scale.

  • ✓

    Enable "Windows Event Forwarding" via the Group Policy setting "Configure target Subscription Manager" under Computer Configuration > Administrative Templates > Windows Components > Event Forwarding.

    Why this is correct

    This Group Policy setting configures the source computers to forward events to a specific collector. It specifies the collector's FQDN and the subscription manager, enabling automatic forwarding of security events. This is the correct method to centrally collect logs from many workstations without manual configuration on each machine, and it supports filtering and scalability for enterprise environments.

  • ✗

    Configure the "Maximum Log Size" for the Security log to a large value and enable "Overwrite events as needed".

    Why it's wrong here

    Increasing log size and enabling overwrite helps retain more events locally but does not forward them to a central collector. This approach leaves logs vulnerable to tampering or loss if the workstation is compromised. It also does not provide correlation across multiple machines, which is a key requirement for centralized monitoring and incident response.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.