GSEC Windows Automation and Auditing Practice Question
A security administrator wants to enable PowerShell script block logging on a Windows 10 workstation to capture suspicious script content. The administrator runs `Get-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging'`. Which registry value should be configured to enable this feature?
⚠ Common exam trap
Many candidates confuse script block logging with module logging or transcription, or selecting a similarly named value like EnableScriptBlockInvocationLogging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EnableScriptBlockLogging (DWORD) set to 1
Script block logging is enabled by setting the EnableScriptBlockLogging DWORD value to 1 under the ScriptBlockLogging registry key. This logs script blocks to Event ID 4104, providing visibility into potentially malicious scripts. Other logging features like module logging and transcription serve different purposes and are configured elsewhere.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EnableTranscripting (DWORD) set to 1
Why it's wrong here
EnableTranscripting enables transcription, which records all PowerShell input and output to text files. It is configured under a different key and does not log script blocks to the event log. While transcription can be useful, it does not provide the same centralized logging as script block logging and is not the value under ScriptBlockLogging.
- ✗
EnableScriptBlockInvocationLogging (DWORD) set to 1
Why it's wrong here
EnableScriptBlockInvocationLogging is a related but separate setting that logs the start and stop of script block invocations. It is not the primary value for logging script block content. The correct value for capturing script content is EnableScriptBlockLogging. This option is a plausible distractor because it sounds similar but does not enable the desired logging.
- ✓
EnableScriptBlockLogging (DWORD) set to 1
Why this is correct
The EnableScriptBlockLogging registry value, when set to 1, enables script block logging. This causes PowerShell to log script blocks to the Windows Event Log, specifically Event ID 4104. This is the correct value to configure under the ScriptBlockLogging key. It is a common security control to detect malicious scripts and is often set via Group Policy or manually.
- ✗
EnableModuleLogging (DWORD) set to 1
Why it's wrong here
EnableModuleLogging is used for module logging, which logs pipeline execution details for specified modules. It is configured under a different registry key and does not enable script block logging. Module logging captures cmdlet invocations but not the full script content. Setting this value would not achieve the goal of logging script blocks.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.