Courseiva

GSEC Windows Automation and Auditing Practice Question

A security analyst at a financial firm suspects that an attacker used a service account to create a new local administrator on a Windows 10 workstation. The analyst runs `auditpol /get /category:*` and sees that the 'Account Management' subcategory is set to 'No Auditing'. Which action should the analyst take to capture future events of this type while minimizing noise?

⚠ Common exam trap

The trap here is assuming that Logon/Logoff or Policy Change auditing will capture account creation events, when only the Account Management subcategory records those specific actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the 'Account Management' subcategory with both Success and Failure auditing.

The Account Management subcategory is specifically designed to log changes to user accounts and groups, including creation, deletion, and membership modifications. Enabling both Success and Failure auditing ensures that any attempt to add a local administrator is recorded, whether it succeeds or fails. This directly targets the suspicious activity while avoiding the overhead of unrelated audit categories.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable the 'Account Management' subcategory with both Success and Failure auditing.

    Why this is correct

    Enabling Success and Failure auditing for the Account Management subcategory captures events such as user account creation (Event ID 4720) and group membership changes (Event ID 4728/4732). This directly addresses the scenario by logging both successful and failed attempts to create or modify local accounts, which is necessary to detect an attacker adding a local administrator. It also provides a balance of visibility without enabling entire categories that would generate excessive noise.

  • ✗

    Enable the 'Policy Change' subcategory with Success auditing only.

    Why it's wrong here

    Policy Change auditing tracks modifications to audit policy, trust relationships, and other security policy settings, such as Event ID 4719. It does not record the creation of local user accounts or changes to local group membership. While detecting policy changes is valuable, it would not capture the attacker's action of adding a local administrator, leaving the primary threat unmonitored.

  • ✗

    Enable the 'Detailed Tracking' subcategory with Success auditing only.

    Why it's wrong here

    Detailed Tracking auditing monitors process creation, process termination, and DPAPI activity, including Event ID 4688. It does not log account management events such as user creation or group modifications. Enabling it would generate a high volume of process-related events without providing the specific visibility needed to detect a new local administrator being added by a service account.

  • ✗

    Enable the 'Logon/Logoff' subcategory with Failure auditing only.

    Why it's wrong here

    Logon/Logoff auditing records authentication events like successful or failed logons (Event IDs 4624/4625), not account creation or group membership changes. Enabling only Failure auditing would miss successful logons by the attacker and would not capture the creation of a new local administrator. This option does not address the specific activity described and would leave the account management actions unlogged.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.