Courseiva

GSEC · topic practice

Windows Automation and Auditing practice questions

This GSEC domain covers auditing and automating Windows hosts with native tooling. Questions present realistic scenarios: verifying local group membership and scheduled tasks, enforcing PowerShell script signing, reading audit policy output, and enabling object access auditing on file shares. Expect command-level answers using PowerShell, auditpol, and Group Policy rather than third-party products.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Windows Automation and Auditing

What the exam tests

What to know about Windows Automation and Auditing

Be able to run and read PowerShell auditing commands, set script-signing policy, interpret auditpol configuration output, and enable file access auditing correctly. The key is knowing that audit policy configuration and the SACL must both be set before Windows records file read or write events.

Using PowerShell cmdlets such as Get-LocalGroupMember and Get-ScheduledTask to audit a host

Enforcing AllSigned execution policy via Set-ExecutionPolicy to require digitally signed scripts

Interpreting auditpol output to determine Account Logon audit configuration state

Enabling object access auditing through Group Policy or auditpol for file read/write events

Watch out for

Common Windows Automation and Auditing exam traps

  • ▸Confusing execution policy scope: Set-ExecutionPolicy changes policy but is not a security boundary and can be bypassed.
  • ▸Assuming auditpol shows events; it only configures policy, while Event Viewer or wevtutil surfaces the records.
  • ▸Enabling object access auditing without configuring a SACL on the target file or folder, so no events are logged.

Practice set

Windows Automation and Auditing questions

20 questions · select your answer, then reveal the explanation

An administrator needs to enforce password complexity across 500 domain-joined Windows workstations without using Group Policy Objects. Which tool is the most efficient choice for this task?

A security analyst needs to quickly identify all Windows services that are configured to start automatically on a Windows 10 workstation. Which PowerShell command should be used?

A security consultant is reviewing the PowerShell execution policy on a Windows Server 2019 used for administrative tasks. The consultant runs `Get-ExecutionPolicy -List` and observes that the MachinePolicy scope is set to AllSigned. Which two statements accurately describe the behavior of PowerShell under this configuration? (Choose two.)

A security analyst is investigating a suspected breach on a Windows Server 2019. The analyst runs the command `wevtutil qe Security /q:"*[System[(EventID=1102)]]" /f:text` and finds no results. What does this indicate about the security log?

A security analyst is investigating a potential compromise on a Windows Server 2019 domain controller. The analyst wants to identify all accounts that were used to perform privileged operations, such as modifying domain admin group membership, within the last 24 hours. Which Windows Security event log source and event ID should the analyst focus on?

You are auditing a Windows server and need to identify which user accounts have recently utilized elevated privileges. Which specific Event ID should you prioritize in the Security log?

Refer to the exhibit. What is the current configuration state for auditing 'Account Logon' events based on the provided output?

Exhibit

C:\> auditpol /get /category:"Account Logon"
System audit policy
Category/Subcategory Setting
Account Logon
  Credential Validation Success and Failure

Which TWO of the following PowerShell commands would you use to audit current local group membership and verify existing scheduled tasks on a compromised Windows server?

You are hardening a Windows environment and must restrict the use of PowerShell to only digitally signed scripts. Which command should you execute?

Which Windows component is responsible for the centralized management of security configurations, including password policies and user rights, across a domain?

Which THREE of the following are considered best practices for auditing Windows event logs to enhance security monitoring?

Which PowerShell command is used to display the current status of advanced auditing policies on a Windows system?

You are a security analyst at a company that suspects an insider is exfiltrating files from a Windows Server 2019 file server. You need to enable auditing to record every time a file is read or written on a specific shared folder, while minimizing the volume of unrelated events. Which of the following should you do first?

A security administrator needs to ensure that all Windows 10 workstations in a domain automatically forward their security event logs to a central collector to prevent tampering and enable correlation. The organization uses Group Policy. Which of the following should the administrator configure?

You are a security analyst at a financial firm. A Windows Server 2019 domain controller is suspected of unauthorized access. You need to determine which user accounts were used to log on interactively to that server during the past week. Which Windows Event ID should you examine?

You are a security administrator for a Windows environment. You need to audit changes to critical files on a file server to detect unauthorized modifications. You decide to use Windows auditing features. Which TWO of the following steps must you perform to enable and capture file modification events? (Choose two.)

A security analyst at a financial firm suspects that an attacker used a service account to create a new local administrator on a Windows 10 workstation. The analyst runs `auditpol /get /category:*` and sees that the 'Account Management' subcategory is set to 'No Auditing'. Which action should the analyst take to capture future events of this type while minimizing noise?

You are a security consultant reviewing a Windows Server 2016 environment. The client wants to ensure that all administrative actions are logged and can be traced back to individual administrators. Currently, all administrators use a shared domain admin account. Which security control should you recommend to meet this requirement?

A junior administrator needs to quickly identify all Windows services that are currently set to start automatically but are not running on a Windows Server 2016. Which PowerShell command should the administrator use?

A security administrator wants to enable PowerShell script block logging on a Windows 10 workstation to capture suspicious script content. The administrator runs `Get-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging'`. Which registry value should be configured to enable this feature?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Windows Automation and Auditing sessions

Start a Windows Automation and Auditing only practice session

Every question in these sessions is drawn from the Windows Automation and Auditing domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Windows Automation and Auditing?
Be able to run and read PowerShell auditing commands, set script-signing policy, interpret auditpol configuration output, and enable file access auditing correctly. The key is knowing that audit policy configuration and the SACL must both be set before Windows records file read or write events.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Windows Automation and Auditing questions in a focused session?
Yes — the session launcher on this page draws every question from the Windows Automation and Auditing domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.