Courseiva

CCNA Windows Automation And Auditing Questions

16 questions · Windows Automation And Auditing topic · All types, answers revealed

1
MCQmedium

A security analyst at a financial institution is auditing a Windows Server 2019 domain controller. The organization's policy requires that all authentication attempts, including failed logons, be logged for forensic analysis. The analyst runs 'auditpol /get /category:*' and notices that the 'Logon/Logoff' category shows 'No Auditing'. Which command should the analyst use to enable auditing for both successful and failed logon events?

A.auditpol /set /category:"Logon/Logoff" /success:disable /failure:enable
B.auditpol /set /category:"Account Logon" /success:enable /failure:enable
C.auditpol /set /subcategory:"Logon" /success:enable /failure:enable
D.auditpol /set /category:"Logon/Logoff" /success:enable /failure:enable
AnswerD

This command uses auditpol to configure the Logon/Logoff category to audit both successful and failed events. It directly addresses the requirement to log all authentication attempts, including failed logons, by setting both success and failure auditing. This is the correct way to enable auditing for the specified category, ensuring compliance with the organization's policy.

Why this answer

To audit both successful and failed logon events, the analyst must enable both success and failure auditing for the Logon/Logoff category. The auditpol command with the /category parameter and both /success:enable and /failure:enable correctly configures this. Other options either target the wrong category, omit necessary parameters, or disable success auditing, failing to meet the policy requirement.

Exam trap

The trap here is confusing the 'Account Logon' category with 'Logon/Logoff', as they audit different authentication events.

2
Multi-Selecthard

You are a security administrator for a Windows environment. You need to audit changes to critical files on a file server to detect unauthorized modifications. You decide to use Windows auditing features. Which TWO of the following steps must you perform to enable and capture file modification events? (Choose two.)

Select 2 answers
A.Set up a Windows Management Instrumentation (WMI) event subscription to monitor file changes.
B.Configure a System Access Control List (SACL) on the files to be monitored.
C.Enable the 'Audit process tracking' policy.
D.Configure a Discretionary Access Control List (DACL) to deny write access to all users.
E.Enable the 'Audit object access' policy in Group Policy.
AnswersB, E

A SACL defines which users or groups and which access types (e.g., Write, Delete) should be audited. You must set a SACL on each file or folder you want to monitor. This is done via the file's Properties -> Security -> Advanced -> Auditing tab. Without a SACL, no auditing occurs for that object, even if the audit policy is enabled.

Why this answer

To audit file modifications, you must first enable the 'Audit object access' policy, which allows the system to log access attempts. Then, you must set a SACL on each file or folder to specify what to audit. Only with both steps will Event ID 4663 (an attempt was made to access an object) be logged for modifications.

The other options do not enable file auditing.

Exam trap

The trap here is assuming that setting a SACL alone is sufficient, or confusing DACLs with SACLs; both audit policy and SACL are required.

3
MCQmedium

Refer to the exhibit. What is the current configuration state for auditing 'Account Logon' events based on the provided output?

A.Only failure events are being audited
B.Both success and failure are being audited
C.Auditing is completely disabled for this category
D.Only success events are being audited
AnswerB

The display lists 'Success and Failure' under the credential validation subcategory. This confirms that the security policy is set to log every authentication event, allowing for full visibility into legitimate login patterns and potential unauthorized access attempts targeting user credentials.

Why this answer

The output indicates that the 'Account Logon' category is configured to audit both success and failure for credential validation. Auditing this is essential because it captures domain-wide authentication attempts occurring on the domain controller. This visibility is vital for identifying brute-force attacks or anomalous login behavior, providing a foundation for effective incident response and forensic analysis within the Windows infrastructure.

Exam trap

Candidates often misread the audit policy output format, failing to distinguish between the 'Success' and 'Failure' columns, leading them to assume only one is being audited.

4
MCQmedium

You are a security analyst at a company that suspects an insider is exfiltrating files from a Windows Server 2019 file server. You need to enable auditing to record every time a file is read or written on a specific shared folder, while minimizing the volume of unrelated events. Which of the following should you do first?

A.Enable the "Audit Handle Manipulation" subcategory to capture file access attempts.
B.Configure a basic audit policy by enabling "Audit object access" in the Local Security Policy.
C.Enable the "Audit File System" subcategory under Object Access in Advanced Audit Policy Configuration.
D.Create a new Data Collector Set in Performance Monitor to track file access on the shared folder.
AnswerC

Advanced Audit Policy Configuration provides granular control over object access auditing. Enabling the Audit File System subcategory allows you to log file read/write events only when a system access control list (SACL) is set on the target folder. This minimizes noise by targeting the specific subcategory rather than the broad legacy policy, and it is the necessary first step before configuring the SACL on the folder itself.

Why this answer

To audit file reads and writes on a specific folder, you must first enable the Audit File System subcategory in Advanced Audit Policy Configuration. This provides granular control and reduces noise compared to legacy basic auditing. After enabling this subcategory, you would then configure a system access control list (SACL) on the folder to specify which users and access types to audit.

This combination ensures that only relevant events are logged, aligning with the principle of least privilege and efficient monitoring.

Exam trap

The trap here is confusing basic audit policy with advanced audit policy, or selecting a performance monitoring tool instead of a security auditing feature.

5
MCQmedium

A security analyst at a financial firm suspects that an attacker used a service account to create a new local administrator on a Windows 10 workstation. The analyst runs `auditpol /get /category:*` and sees that the 'Account Management' subcategory is set to 'No Auditing'. Which action should the analyst take to capture future events of this type while minimizing noise?

A.Enable the 'Account Management' subcategory with both Success and Failure auditing.
B.Enable the 'Policy Change' subcategory with Success auditing only.
C.Enable the 'Detailed Tracking' subcategory with Success auditing only.
D.Enable the 'Logon/Logoff' subcategory with Failure auditing only.
AnswerA

Enabling Success and Failure auditing for the Account Management subcategory captures events such as user account creation (Event ID 4720) and group membership changes (Event ID 4728/4732). This directly addresses the scenario by logging both successful and failed attempts to create or modify local accounts, which is necessary to detect an attacker adding a local administrator. It also provides a balance of visibility without enabling entire categories that would generate excessive noise.

Why this answer

The Account Management subcategory is specifically designed to log changes to user accounts and groups, including creation, deletion, and membership modifications. Enabling both Success and Failure auditing ensures that any attempt to add a local administrator is recorded, whether it succeeds or fails. This directly targets the suspicious activity while avoiding the overhead of unrelated audit categories.

Exam trap

The trap here is assuming that Logon/Logoff or Policy Change auditing will capture account creation events, when only the Account Management subcategory records those specific actions.

6
MCQmedium

You are a security analyst at a financial firm. A Windows Server 2019 domain controller is suspected of unauthorized access. You need to determine which user accounts were used to log on interactively to that server during the past week. Which Windows Event ID should you examine?

A.Event ID 4648
B.Event ID 4624
C.Event ID 4672
D.Event ID 4634
AnswerB

Event ID 4624 is logged on the local computer when a logon session is created. It includes the Logon Type, which indicates how the logon occurred. For interactive logons, the Logon Type is 2. By filtering 4624 events with Logon Type 2 on the domain controller, you can identify which accounts were used for interactive logons, directly answering the scenario.

Why this answer

Interactive logons generate Event ID 4624 with Logon Type 2. This event records the account name, logon type, and other details, making it the primary source for identifying which accounts were used for interactive access. Other events like 4634, 4648, and 4672 serve different purposes and do not directly show interactive logon activity.

Exam trap

The trap here is confusing logon-related events, such as 4634 (logoff) or 4648 (explicit credential use), with the event that actually records interactive logons.

7
MCQmedium

Which PowerShell command is used to display the current status of advanced auditing policies on a Windows system?

A.Get-AuditPolicy
B.auditpol /get /category:*
C.Get-SecurityPolicy -Advanced
D.Get-EventLog -List
AnswerB

This is the correct command-line utility used to query the system's current advanced audit policy. It outputs the status of all audited categories, allowing administrators to confirm that required auditing features are active across the entire system for comprehensive security coverage.

Why this answer

The 'auditpol /get /category:*' command is the standard CLI method to verify the current configuration of the Advanced Audit Policy. Unlike legacy policies, advanced policies allow for granular control over what events are logged, providing better precision for security analysis. Verifying these settings is a standard step in ensuring that the security telemetry collected aligns with the organizational compliance requirements.

Exam trap

Candidates often guess 'auditpol /list' or 'auditpol /query' instead of the correct '/get' switch, as these common CLI verbs feel more intuitive for retrieving configuration status.

8
MCQeasy

A junior administrator needs to quickly identify all Windows services that are currently set to start automatically but are not running on a Windows Server 2016. Which PowerShell command should the administrator use?

A.Get-Service | Where-Object {$_.StartType -eq 'Automatic' -and $_.Status -ne 'Running'}
B.Get-Service -StartType Automatic | Where-Object {$_.Status -eq 'Stopped'}
C.Get-Service | Where-Object {$_.StartType -eq 'Automatic' -or $_.Status -eq 'Stopped'}
D.Get-Service | Where-Object {$_.StartType -eq 'Automatic' -and $_.Status -eq 'Stopped'}
AnswerA

This command filters services where the StartType is 'Automatic' and the Status is not 'Running'. It directly returns the list of automatic services that are stopped or in another non-running state. The Where-Object cmdlet evaluates each service object, and the condition uses -and to combine both criteria. This is the most straightforward and accurate way to achieve the goal.

Why this answer

To find automatic services that are not running, you must filter by StartType equal to 'Automatic' and Status not equal to 'Running'. The correct command uses Where-Object with -and and -ne to capture all non-running states. This ensures you don't miss services that are paused or in transition.

Exam trap

The trap here is assuming that 'not running' means only 'Stopped' or using -or instead of -and, which broadens the results incorrectly.

9
Multi-Selectmedium

Which THREE of the following are considered best practices for auditing Windows event logs to enhance security monitoring?

Select 3 answers
A.Centralize logs to a SIEM for long-term storage
B.Increase maximum log size to prevent log overwriting
C.Audit every single file access on the system
D.Enable auditing of process creation and logons
E.Require domain admins to clear logs daily
AnswersA, B, D

Centralizing logs is crucial because local logs can be cleared by an attacker to hide their tracks. A SIEM ensures that logs are stored securely off-host, allowing for correlation and analysis that would be impossible if limited only to local disk space.

Why this answer

Effective log auditing relies on consistency, central collection, and meaningful alerting. By setting a large log size, ensuring remote aggregation, and auditing critical security-related events, organizations move from reactive to proactive monitoring. These practices are essential for ensuring that evidence is preserved during an incident and that alerts are generated for high-value security events before they are rotated out of the local logs.

Exam trap

Candidates often suggest auditing everything, which leads to log saturation and performance issues. They fail to understand that effective auditing focuses on specific, high-value security events like process creation.

10
MCQhard

A security administrator needs to ensure that all Windows 10 workstations in a domain automatically forward their security event logs to a central collector to prevent tampering and enable correlation. The organization uses Group Policy. Which of the following should the administrator configure?

A.Enable the "Audit: Force audit policy subcategory settings" policy and set the Security log to archive when full.
B.Deploy a custom PowerShell script via Group Policy that runs at startup to copy the Security.evtx file to a network share.
C.Enable "Windows Event Forwarding" via the Group Policy setting "Configure target Subscription Manager" under Computer Configuration > Administrative Templates > Windows Components > Event Forwarding.
D.Configure the "Maximum Log Size" for the Security log to a large value and enable "Overwrite events as needed".
AnswerC

This Group Policy setting configures the source computers to forward events to a specific collector. It specifies the collector's FQDN and the subscription manager, enabling automatic forwarding of security events. This is the correct method to centrally collect logs from many workstations without manual configuration on each machine, and it supports filtering and scalability for enterprise environments.

Why this answer

Windows Event Forwarding (WEF) is the native mechanism for collecting events from multiple computers. The Group Policy setting "Configure target Subscription Manager" tells source computers where to send events. The collector then uses subscriptions to filter and store events.

This approach is scalable, secure, and supports real-time forwarding. It also allows the collector to use a dedicated service account and can be configured to use HTTPS for encryption, preventing tampering and enabling centralized analysis.

Exam trap

The trap here is assuming that increasing local log size or copying log files manually achieves centralization, when the exam expects knowledge of the built-in Windows Event Forwarding feature.

11
MCQmedium

You are auditing a Windows server and need to identify which user accounts have recently utilized elevated privileges. Which specific Event ID should you prioritize in the Security log?

A.Event ID 4624
B.Event ID 4672
C.Event ID 4720
D.Event ID 1102
AnswerB

This event explicitly indicates that a logon session has been assigned special privileges. It is the definitive audit log entry for identifying administrative access at the moment of login, providing a clear trail for security analysts monitoring for unauthorized privilege usage.

Why this answer

Event ID 4672 is generated immediately upon a successful logon when a user is assigned special privileges, such as SeDebugPrivilege or SeBackupPrivilege. Auditing this ID allows administrators to track the lifecycle of administrative access, effectively mapping privilege escalation to specific user sessions. Monitoring this is critical for detecting potential account compromise or unauthorized administrative activity within the Windows environment.

Exam trap

Test-takers often look for standard successful logon IDs like 4624 instead of checking for special privilege assignment events during administrative sessions.

12
MCQmedium

You are a security consultant reviewing a Windows Server 2016 environment. The client wants to ensure that all administrative actions are logged and can be traced back to individual administrators. Currently, all administrators use a shared domain admin account. Which security control should you recommend to meet this requirement?

A.Configure a Group Policy Object to enable 'Audit process tracking' for all servers.
B.Enable the 'Audit: Force audit policy subcategory settings' policy.
C.Implement separate administrative accounts for each administrator.
D.Enable 'Audit: Shut down system immediately if unable to log security audits'.
AnswerC

Using separate accounts ensures that each administrator's actions are logged under their unique account. This allows auditing and traceability. Shared accounts prevent attribution. By implementing individual accounts, you can track who performed which action. This is a fundamental principle of accountability and directly solves the scenario's requirement.

Why this answer

The core issue is that shared accounts prevent attribution. To trace administrative actions to individuals, each administrator must have a unique account. This ensures that audit logs record the specific user who performed each action.

Other options address audit policy settings but do not solve the fundamental problem of shared credentials.

Exam trap

The trap here is focusing on audit policy configuration when the real problem is the use of a shared account, which makes individual attribution impossible regardless of audit settings.

13
MCQeasy

Which Windows component is responsible for the centralized management of security configurations, including password policies and user rights, across a domain?

A.Windows Registry
B.Group Policy Objects
C.Task Scheduler
D.Microsoft Management Console
AnswerB

GPOs provide the primary mechanism for applying security policies and configurations across a domain. They allow for granular control and automated enforcement, ensuring that hardening standards are consistently applied to all managed workstations and servers in the environment.

Why this answer

Group Policy Objects (GPOs) allow administrators to define specific configurations for users and computers across the entire domain. By centralizing these settings, security teams can ensure consistent enforcement of hardening standards and compliance policies. Proper GPO management is essential for minimizing the attack surface and maintaining a uniform security baseline in any enterprise Windows architecture.

Exam trap

Candidates often confuse GPOs with 'Local Security Policy' (secpol.msc). While both manage settings, GPOs are specifically the tool for centralized domain-wide management.

14
MCQmedium

You are hardening a Windows environment and must restrict the use of PowerShell to only digitally signed scripts. Which command should you execute?

A.Set-ExecutionPolicy RemoteSigned
B.Set-ExecutionPolicy AllSigned
C.Set-ExecutionPolicy Unrestricted
D.Set-ExecutionPolicy Bypass
AnswerB

The AllSigned policy mandates that all scripts, including local ones, must be digitally signed by a trusted publisher. This is the recommended security posture for preventing unauthorized script execution and ensuring integrity, making it a critical hardening step for any secure environment.

Why this answer

Setting the execution policy to 'AllSigned' forces the system to verify that every script has been signed by a trusted publisher. This is a fundamental security control that prevents the execution of unauthorized or tampered scripts. Implementing this policy significantly reduces the attack surface for fileless malware that relies on unconstrained execution of PowerShell commands and scripts.

Exam trap

Candidates often confuse 'AllSigned' with 'RemoteSigned'. 'AllSigned' requires every script to be signed, whereas 'RemoteSigned' only requires signatures for scripts downloaded from the internet, making it less restrictive.

15
Multi-Selecthard

Which TWO of the following PowerShell commands would you use to audit current local group membership and verify existing scheduled tasks on a compromised Windows server?

Select 2 answers
A.Get-LocalGroupMember -Group Administrators
B.Get-ScheduledTask
C.Get-Process -IncludeUserName
D.Get-Service | Where-Object {$_.Status -eq 'Running'}
E.Get-WinEvent -LogName Security
AnswersA, B

This cmdlet allows an auditor to list all members of the local Administrators group. Monitoring this group is vital, as attackers often add malicious accounts or elevated service accounts to maintain control over the compromised host during the post-exploitation phase.

Why this answer

Effective auditing requires querying local identity stores and task schedules. 'Get-LocalGroupMember' provides a snapshot of accounts with elevated or specific access, while 'Get-ScheduledTask' identifies persistent malicious mechanisms. Understanding these commands is critical for GSEC professionals to perform rapid host-based forensics, as these two areas are frequent targets for persistence and lateral movement by attackers.

Exam trap

Candidates often select commands related to Active Directory or system-wide auditing rather than host-specific local commands. They fail to distinguish between domain-level management and local server-level forensic auditing.

16
MCQmedium

A security administrator wants to enable PowerShell script block logging on a Windows 10 workstation to capture suspicious script content. The administrator runs `Get-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging'`. Which registry value should be configured to enable this feature?

A.EnableTranscripting (DWORD) set to 1
B.EnableScriptBlockInvocationLogging (DWORD) set to 1
C.EnableScriptBlockLogging (DWORD) set to 1
D.EnableModuleLogging (DWORD) set to 1
AnswerC

The EnableScriptBlockLogging registry value, when set to 1, enables script block logging. This causes PowerShell to log script blocks to the Windows Event Log, specifically Event ID 4104. This is the correct value to configure under the ScriptBlockLogging key. It is a common security control to detect malicious scripts and is often set via Group Policy or manually.

Why this answer

Script block logging is enabled by setting the EnableScriptBlockLogging DWORD value to 1 under the ScriptBlockLogging registry key. This logs script blocks to Event ID 4104, providing visibility into potentially malicious scripts. Other logging features like module logging and transcription serve different purposes and are configured elsewhere.

Exam trap

The trap here is confusing script block logging with module logging or transcription, or selecting a similarly named value like EnableScriptBlockInvocationLogging.

Ready to test yourself?

Try a timed practice session using only Windows Automation And Auditing questions.