GSEC Windows Automation and Auditing Practice Question
Which PowerShell command is used to display the current status of advanced auditing policies on a Windows system?
⚠ Common exam trap
Candidates often guess 'auditpol /list' or 'auditpol /query' instead of the correct '/get' switch, as these common CLI verbs feel more intuitive for retrieving configuration status.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
auditpol /get /category:*
The 'auditpol /get /category:*' command is the standard CLI method to verify the current configuration of the Advanced Audit Policy. Unlike legacy policies, advanced policies allow for granular control over what events are logged, providing better precision for security analysis. Verifying these settings is a standard step in ensuring that the security telemetry collected aligns with the organizational compliance requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Get-AuditPolicy
Why it's wrong here
There is no native PowerShell cmdlet named Get-AuditPolicy. While users often look for PowerShell-specific equivalents for system tasks, the auditing framework still relies on the auditpol.exe utility for both querying and setting the advanced auditing policy configuration.
- ✓
auditpol /get /category:*
Why this is correct
This is the correct command-line utility used to query the system's current advanced audit policy. It outputs the status of all audited categories, allowing administrators to confirm that required auditing features are active across the entire system for comprehensive security coverage.
- ✗
Get-SecurityPolicy -Advanced
Why it's wrong here
This cmdlet does not exist in the default Windows PowerShell module set. Relying on incorrect commands can lead to wasted time during an audit. Administrators should use the built-in auditpol.exe utility, which is designed specifically for managing and inspecting the system's auditing configuration.
- ✗
Get-EventLog -List
Why it's wrong here
This cmdlet lists the available event logs on the system, such as System, Application, and Security. It provides information about the logs themselves, but it does not reveal the audit policy settings that dictate which specific security events are actually being captured.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.