GSEC Windows Security Infrastructure Practice Question
A security analyst is reviewing the audit policy on a Windows Server 2022 domain controller. The analyst needs to ensure that the domain controller records detailed information about changes to user account attributes, including old and new values, to support forensic investigations. Which audit policy should the analyst enable?
⚠ Common exam trap
Many candidates confuse Audit User Account Management, which logs account management events but not detailed attribute changes, with Audit Directory Service Changes, which specifically records old and new values of modified directory objects.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit Directory Service Changes
To capture detailed information about changes to user account attributes, including old and new values, the analyst must enable Audit Directory Service Changes. This policy logs modifications to Active Directory objects with before-and-after values, which is essential for forensic investigations. Other audit policies focus on different event types and do not provide this level of detail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Audit User Account Management
Why it's wrong here
Audit User Account Management logs events when user accounts are created, changed, deleted, renamed, disabled, enabled, locked out, or unlocked. It does not provide detailed before-and-after values for modified attributes. It is useful for detecting account changes but lacks the granularity needed for forensic analysis of specific attribute modifications.
- ✓
Audit Directory Service Changes
Why this is correct
Audit Directory Service Changes logs events when objects in Active Directory are modified, including the old and new values of changed attributes. This policy is specifically designed to track changes to directory objects, providing the detailed information required for forensic investigations of user account modifications.
- ✗
Audit Account Logon Events
Why it's wrong here
Audit Account Logon Events records events related to user authentication, such as successful or failed logon attempts. It does not capture changes to account attributes or directory objects. Enabling this policy would not provide the detailed attribute change information the analyst needs for forensic analysis.
- ✗
Audit Policy Change
Why it's wrong here
Audit Policy Change logs changes to audit policies themselves, such as when an audit policy is modified. It does not track changes to user account attributes. While important for monitoring policy tampering, it does not fulfill the requirement for detailed attribute change auditing.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.