GSEC Windows Automation and Auditing Practice Question
You are a security administrator for a Windows environment. You need to audit changes to critical files on a file server to detect unauthorized modifications. You decide to use Windows auditing features. Which TWO of the following steps must you perform to enable and capture file modification events? (Choose two.)
⚠ Common exam trap
The trap here is assuming that setting a SACL alone is sufficient, or confusing DACLs with SACLs; both audit policy and SACL are required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a System Access Control List (SACL) on the files to be monitored.
To audit file modifications, you must first enable the 'Audit object access' policy, which allows the system to log access attempts. Then, you must set a SACL on each file or folder to specify what to audit. Only with both steps will Event ID 4663 (an attempt was made to access an object) be logged for modifications. The other options do not enable file auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set up a Windows Management Instrumentation (WMI) event subscription to monitor file changes.
Why it's wrong here
WMI event subscriptions can monitor file changes, but they are not part of the Windows auditing feature set. They require custom scripting and are not the standard method for file auditing. The question specifies using Windows auditing features, so WMI is not the correct approach. Additionally, WMI subscriptions can be complex and are not enabled by default.
- ✓
Configure a System Access Control List (SACL) on the files to be monitored.
Why this is correct
A SACL defines which users or groups and which access types (e.g., Write, Delete) should be audited. You must set a SACL on each file or folder you want to monitor. This is done via the file's Properties -> Security -> Advanced -> Auditing tab. Without a SACL, no auditing occurs for that object, even if the audit policy is enabled.
- ✗
Enable the 'Audit process tracking' policy.
Why it's wrong here
Audit process tracking logs events like process creation and termination, which is unrelated to file modification auditing. It does not capture file access or changes. While it can be useful for other security monitoring, it does not fulfill the requirement to audit changes to critical files. Therefore, it is not a necessary step for this scenario.
- ✗
Configure a Discretionary Access Control List (DACL) to deny write access to all users.
Why it's wrong here
A DACL controls who can access a file and what they can do, but it does not enable auditing. In fact, denying write access to all users would prevent modifications altogether, which might stop the need for auditing but does not help detect unauthorized changes if they occur through other means. The goal is to audit, not to block.
- ✓
Enable the 'Audit object access' policy in Group Policy.
Why this is correct
Enabling 'Audit object access' in Group Policy (Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> Object Access) is required to allow the system to log access attempts to files and folders. Without this policy enabled, even if you set SACLs on files, no events will be generated. This is a fundamental prerequisite for file auditing.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.