Courseiva

GSEC Windows Automation and Auditing Practice Question

Which PowerShell command is used to display the current status of advanced auditing policies on a Windows system?

⚠ Common exam trap

Candidates often guess 'auditpol /list' or 'auditpol /query' instead of the correct '/get' switch, as these common CLI verbs feel more intuitive for retrieving configuration status.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

auditpol /get /category:*

The 'auditpol /get /category:*' command is the standard CLI method to verify the current configuration of the Advanced Audit Policy. Unlike legacy policies, advanced policies allow for granular control over what events are logged, providing better precision for security analysis. Verifying these settings is a standard step in ensuring that the security telemetry collected aligns with the organizational compliance requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Get-AuditPolicy

    Why it's wrong here

    There is no native PowerShell cmdlet named Get-AuditPolicy. While users often look for PowerShell-specific equivalents for system tasks, the auditing framework still relies on the auditpol.exe utility for both querying and setting the advanced auditing policy configuration.

  • ✓

    auditpol /get /category:*

    Why this is correct

    This is the correct command-line utility used to query the system's current advanced audit policy. It outputs the status of all audited categories, allowing administrators to confirm that required auditing features are active across the entire system for comprehensive security coverage.

  • ✗

    Get-SecurityPolicy -Advanced

    Why it's wrong here

    This cmdlet does not exist in the default Windows PowerShell module set. Relying on incorrect commands can lead to wasted time during an audit. Administrators should use the built-in auditpol.exe utility, which is designed specifically for managing and inspecting the system's auditing configuration.

  • ✗

    Get-EventLog -List

    Why it's wrong here

    This cmdlet lists the available event logs on the system, such as System, Application, and Security. It provides information about the logs themselves, but it does not reveal the audit policy settings that dictate which specific security events are actually being captured.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.