A security analyst at a financial institution is auditing a Windows Server 2019 domain controller. The organization's policy requires that all authentication attempts, including failed logons, be logged for forensic analysis. The analyst runs 'auditpol /get /category:*' and notices that the 'Logon/Logoff' category shows 'No Auditing'. Which command should the analyst use to enable auditing for both successful and failed logon events?
This command uses auditpol to configure the Logon/Logoff category to audit both successful and failed events. It directly addresses the requirement to log all authentication attempts, including failed logons, by setting both success and failure auditing. This is the correct way to enable auditing for the specified category, ensuring compliance with the organization's policy.
Why this answer
To audit both successful and failed logon events, the analyst must enable both success and failure auditing for the Logon/Logoff category. The auditpol command with the /category parameter and both /success:enable and /failure:enable correctly configures this. Other options either target the wrong category, omit necessary parameters, or disable success auditing, failing to meet the policy requirement.
Exam trap
The trap here is confusing the 'Account Logon' category with 'Logon/Logoff', as they audit different authentication events.