GSEC Windows Automation and Auditing Practice Question
Exhibit
C:\> auditpol /get /category:"Account Logon" System audit policy Category/Subcategory Setting Account Logon Credential Validation Success and Failure
Refer to the exhibit. What is the current configuration state for auditing 'Account Logon' events based on the provided output?
⚠ Common exam trap
Candidates often misread the audit policy output format, failing to distinguish between the 'Success' and 'Failure' columns, leading them to assume only one is being audited.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Both success and failure are being audited
The output indicates that the 'Account Logon' category is configured to audit both success and failure for credential validation. Auditing this is essential because it captures domain-wide authentication attempts occurring on the domain controller. This visibility is vital for identifying brute-force attacks or anomalous login behavior, providing a foundation for effective incident response and forensic analysis within the Windows infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Only failure events are being audited
Why it's wrong here
The output explicitly shows that both Success and Failure are configured. A failure-only configuration would likely display 'Failure' without the 'Success' indicator, whereas this output shows the category is fully enabled for the credential validation subcategory, indicating a comprehensive auditing stance.
- ✓
Both success and failure are being audited
Why this is correct
The display lists 'Success and Failure' under the credential validation subcategory. This confirms that the security policy is set to log every authentication event, allowing for full visibility into legitimate login patterns and potential unauthorized access attempts targeting user credentials.
- ✗
Auditing is completely disabled for this category
Why it's wrong here
If auditing were disabled, the subcategory would display 'No Auditing' or be absent from the list. The presence of 'Success and Failure' confirms that the policy is active and capturing the necessary authentication data for security monitoring purposes.
- ✗
Only success events are being audited
Why it's wrong here
The policy output clearly states 'Success and Failure', meaning auditing is not restricted to successful logins. Security policies that only audit successes would leave a massive gap in visibility, failing to detect failed brute-force attempts or credential stuffing attacks.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.