Courseiva
Log Management and SIEM →mediumMultiple Choice

GSEC Log Management and SIEM Practice Question

A security analyst is investigating a potential insider threat. The SIEM has ingested logs from multiple sources, including Windows Security logs, Linux auditd, and VPN concentrators. The analyst needs to determine which user account accessed a sensitive file server at 2:00 AM. Which log source and field should the analyst query to identify the user account that initiated the file access?

⚠ Common exam trap

Candidates often confuse logon events (4624) with object access events (4663), leading to the wrong event ID for file access auditing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Security Event ID 4663 (An attempt was made to access an object) with the SubjectUserName field.

To identify the user account that accessed a sensitive file, the analyst should look for object access auditing events. Windows Security Event ID 4663 is generated when an object is accessed and includes the SubjectUserName, which identifies the account. Filtering by the file server and timestamp yields the specific user. Other log sources either do not record file-level access or provide only indirect information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPN concentrator logs with the UserName field and the AssignedIP field.

    Why it's wrong here

    VPN logs show remote access connections but do not record file-level access. They can indicate which user was connected at 2:00 AM, but not which files they accessed. The analyst needs to correlate VPN logs with file access logs, but the question asks for the log source that directly identifies the user account that initiated the file access. VPN logs alone cannot provide that specific information.

  • ✗

    Linux auditd logs with the key field set to "file_access" and the uid field.

    Why it's wrong here

    Linux auditd can log file accesses if configured with audit rules, but the scenario specifies a sensitive file server, which is likely Windows-based given the other log sources. Even if it were Linux, the uid field provides a numeric user ID, not a username, requiring additional mapping. Without knowing the file server's OS, this is not the best choice. The Windows Security log is more directly applicable if the file server is Windows.

  • ✓

    Windows Security Event ID 4663 (An attempt was made to access an object) with the SubjectUserName field.

    Why this is correct

    Event ID 4663 is generated when an object (like a file) is accessed, provided object access auditing is enabled. The SubjectUserName field identifies the account that attempted the access. By filtering for the file server's object name and the timestamp, the analyst can pinpoint the user. This event is specifically designed for file access auditing, making it the most direct source for this scenario.

  • ✗

    Windows Security Event ID 4624 (An account was successfully logged on) with the TargetUserName field.

    Why it's wrong here

    Event ID 4624 logs successful logons, not file accesses. While it can show that a user logged on to the file server, it does not indicate which files were accessed. The analyst needs to identify the user who accessed a specific file, so a logon event is insufficient. The correct event is 4663, which records object access attempts and includes the user account.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.