Courseiva

GSEC Windows Security Infrastructure Practice Question

A security analyst is reviewing the audit policy on a Windows Server 2022 domain controller. The analyst needs to ensure that the domain controller records detailed information about changes to user account attributes, including old and new values, to support forensic investigations. Which audit policy should the analyst enable?

⚠ Common exam trap

Many candidates confuse Audit User Account Management, which logs account management events but not detailed attribute changes, with Audit Directory Service Changes, which specifically records old and new values of modified directory objects.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Audit Directory Service Changes

To capture detailed information about changes to user account attributes, including old and new values, the analyst must enable Audit Directory Service Changes. This policy logs modifications to Active Directory objects with before-and-after values, which is essential for forensic investigations. Other audit policies focus on different event types and do not provide this level of detail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Audit User Account Management

    Why it's wrong here

    Audit User Account Management logs events when user accounts are created, changed, deleted, renamed, disabled, enabled, locked out, or unlocked. It does not provide detailed before-and-after values for modified attributes. It is useful for detecting account changes but lacks the granularity needed for forensic analysis of specific attribute modifications.

  • ✓

    Audit Directory Service Changes

    Why this is correct

    Audit Directory Service Changes logs events when objects in Active Directory are modified, including the old and new values of changed attributes. This policy is specifically designed to track changes to directory objects, providing the detailed information required for forensic investigations of user account modifications.

  • ✗

    Audit Account Logon Events

    Why it's wrong here

    Audit Account Logon Events records events related to user authentication, such as successful or failed logon attempts. It does not capture changes to account attributes or directory objects. Enabling this policy would not provide the detailed attribute change information the analyst needs for forensic analysis.

  • ✗

    Audit Policy Change

    Why it's wrong here

    Audit Policy Change logs changes to audit policies themselves, such as when an audit policy is modified. It does not track changes to user account attributes. While important for monitoring policy tampering, it does not fulfill the requirement for detailed attribute change auditing.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.