GSEC · domain
Windows Automation and Auditing
This GSEC domain covers auditing and automating Windows hosts with native tooling. Questions present realistic scenarios: verifying local group membership and scheduled tasks, enforcing PowerShell script signing, reading audit policy output, and enabling object access auditing on file shares. Expect command-level answers using PowerShell, auditpol, and Group Policy rather than third-party products.
Focused practice
Practice Windows Automation and Auditing questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Windows Automation and Auditing
Be able to run and read PowerShell auditing commands, set script-signing policy, interpret auditpol configuration output, and enable file access auditing correctly. The key is knowing that audit policy configuration and the SACL must both be set before Windows records file read or write events.
Using PowerShell cmdlets such as Get-LocalGroupMember and Get-ScheduledTask to audit a host
Enforcing AllSigned execution policy via Set-ExecutionPolicy to require digitally signed scripts
Interpreting auditpol output to determine Account Logon audit configuration state
Enabling object access auditing through Group Policy or auditpol for file read/write events
Watch out for
Common Windows Automation and Auditing exam traps
- ▸Confusing execution policy scope: Set-ExecutionPolicy changes policy but is not a security boundary and can be bypassed.
- ▸Assuming auditpol shows events; it only configures policy, while Event Viewer or wevtutil surfaces the records.
- ▸Enabling object access auditing without configuring a SACL on the target file or folder, so no events are logged.
Question index
All Windows Automation and Auditing questions (16)
Click any question to see the full explanation, or start a practice session above.
A security analyst at a financial institution is auditing a Windows Server 2019 domain controller. The organization's policy requires that all authentication attempts, including failed logons, be logged for forensic analysis. The analyst runs 'auditpol /get /category:*' and notices that the 'Logon/Logoff' category shows 'No Auditing'. Which command should the analyst use to enable auditing for both successful and failed logon events?
Medium2You are a security administrator for a Windows environment. You need to audit changes to critical files on a file server to detect unauthorized modifications. You decide to use Windows auditing features. Which TWO of the following steps must you perform to enable and capture file modification events? (Choose two.)
Hard3Refer to the exhibit. What is the current configuration state for auditing 'Account Logon' events based on the provided output?
Medium4You are a security analyst at a company that suspects an insider is exfiltrating files from a Windows Server 2019 file server. You need to enable auditing to record every time a file is read or written on a specific shared folder, while minimizing the volume of unrelated events. Which of the following should you do first?
Medium5A security analyst at a financial firm suspects that an attacker used a service account to create a new local administrator on a Windows 10 workstation. The analyst runs `auditpol /get /category:*` and sees that the 'Account Management' subcategory is set to 'No Auditing'. Which action should the analyst take to capture future events of this type while minimizing noise?
Medium6You are a security analyst at a financial firm. A Windows Server 2019 domain controller is suspected of unauthorized access. You need to determine which user accounts were used to log on interactively to that server during the past week. Which Windows Event ID should you examine?
Medium7Which PowerShell command is used to display the current status of advanced auditing policies on a Windows system?
Medium8A junior administrator needs to quickly identify all Windows services that are currently set to start automatically but are not running on a Windows Server 2016. Which PowerShell command should the administrator use?
Easy9Which THREE of the following are considered best practices for auditing Windows event logs to enhance security monitoring?
Medium10A security administrator needs to ensure that all Windows 10 workstations in a domain automatically forward their security event logs to a central collector to prevent tampering and enable correlation. The organization uses Group Policy. Which of the following should the administrator configure?
Hard11You are auditing a Windows server and need to identify which user accounts have recently utilized elevated privileges. Which specific Event ID should you prioritize in the Security log?
Medium12You are a security consultant reviewing a Windows Server 2016 environment. The client wants to ensure that all administrative actions are logged and can be traced back to individual administrators. Currently, all administrators use a shared domain admin account. Which security control should you recommend to meet this requirement?
Medium13Which Windows component is responsible for the centralized management of security configurations, including password policies and user rights, across a domain?
Easy14You are hardening a Windows environment and must restrict the use of PowerShell to only digitally signed scripts. Which command should you execute?
Medium15Which TWO of the following PowerShell commands would you use to audit current local group membership and verify existing scheduled tasks on a compromised Windows server?
Hard16A security administrator wants to enable PowerShell script block logging on a Windows 10 workstation to capture suspicious script content. The administrator runs `Get-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging'`. Which registry value should be configured to enable this feature?
MediumOther domains
All GSEC exam domains
Frequently asked questions
- What does the Windows Automation and Auditing domain cover on the GSEC exam?
- Be able to run and read PowerShell auditing commands, set script-signing policy, interpret auditpol configuration output, and enable file access auditing correctly. The key is knowing that audit policy configuration and the SACL must both be set before Windows records file read or write events.
- How many questions are in this domain?
- This page lists all 16 Windows Automation and Auditing questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Windows Automation and Auditing questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.