Courseiva

GSEC Windows Automation and Auditing Practice Question

Exhibit

C:\> auditpol /get /category:"Account Logon"
System audit policy
Category/Subcategory Setting
Account Logon
  Credential Validation Success and Failure

Refer to the exhibit. What is the current configuration state for auditing 'Account Logon' events based on the provided output?

⚠ Common exam trap

Candidates often misread the audit policy output format, failing to distinguish between the 'Success' and 'Failure' columns, leading them to assume only one is being audited.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Both success and failure are being audited

The output indicates that the 'Account Logon' category is configured to audit both success and failure for credential validation. Auditing this is essential because it captures domain-wide authentication attempts occurring on the domain controller. This visibility is vital for identifying brute-force attacks or anomalous login behavior, providing a foundation for effective incident response and forensic analysis within the Windows infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Only failure events are being audited

    Why it's wrong here

    The output explicitly shows that both Success and Failure are configured. A failure-only configuration would likely display 'Failure' without the 'Success' indicator, whereas this output shows the category is fully enabled for the credential validation subcategory, indicating a comprehensive auditing stance.

  • ✓

    Both success and failure are being audited

    Why this is correct

    The display lists 'Success and Failure' under the credential validation subcategory. This confirms that the security policy is set to log every authentication event, allowing for full visibility into legitimate login patterns and potential unauthorized access attempts targeting user credentials.

  • ✗

    Auditing is completely disabled for this category

    Why it's wrong here

    If auditing were disabled, the subcategory would display 'No Auditing' or be absent from the list. The presence of 'Success and Failure' confirms that the policy is active and capturing the necessary authentication data for security monitoring purposes.

  • ✗

    Only success events are being audited

    Why it's wrong here

    The policy output clearly states 'Success and Failure', meaning auditing is not restricted to successful logins. Security policies that only audit successes would leave a massive gap in visibility, failing to detect failed brute-force attempts or credential stuffing attacks.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.