GSEC Windows Automation and Auditing Practice Question
You are a security analyst at a company that suspects an insider is exfiltrating files from a Windows Server 2019 file server. You need to enable auditing to record every time a file is read or written on a specific shared folder, while minimizing the volume of unrelated events. Which of the following should you do first?
⚠ Common exam trap
Many candidates confuse basic audit policy with advanced audit policy, or selecting a performance monitoring tool instead of a security auditing feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the "Audit File System" subcategory under Object Access in Advanced Audit Policy Configuration.
To audit file reads and writes on a specific folder, you must first enable the Audit File System subcategory in Advanced Audit Policy Configuration. This provides granular control and reduces noise compared to legacy basic auditing. After enabling this subcategory, you would then configure a system access control list (SACL) on the folder to specify which users and access types to audit. This combination ensures that only relevant events are logged, aligning with the principle of least privilege and efficient monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the "Audit Handle Manipulation" subcategory to capture file access attempts.
Why it's wrong here
Audit Handle Manipulation logs when a handle to an object is created or closed, which can be useful for troubleshooting but generates a high volume of low-value events and does not directly record read/write access to files. It is not the correct subcategory for monitoring file reads and writes; Audit File System is the appropriate choice for object access auditing.
- ✗
Configure a basic audit policy by enabling "Audit object access" in the Local Security Policy.
Why it's wrong here
Basic audit policies aggregate multiple subcategories into one setting and can generate excessive events, making it harder to isolate file access on a specific share. They also lack the granularity of advanced audit policies, which are recommended for targeted monitoring. While it may work, it is not the best first step because it does not provide the precision needed to minimize unrelated events.
- ✓
Enable the "Audit File System" subcategory under Object Access in Advanced Audit Policy Configuration.
Why this is correct
Advanced Audit Policy Configuration provides granular control over object access auditing. Enabling the Audit File System subcategory allows you to log file read/write events only when a system access control list (SACL) is set on the target folder. This minimizes noise by targeting the specific subcategory rather than the broad legacy policy, and it is the necessary first step before configuring the SACL on the folder itself.
- ✗
Create a new Data Collector Set in Performance Monitor to track file access on the shared folder.
Why it's wrong here
Performance Monitor Data Collector Sets are designed for performance metrics such as disk I/O or CPU usage, not security auditing of file access. They cannot record individual file read/write operations by user. This approach would not provide the required security event logs and would fail to meet the investigation's need to track who accessed specific files.
Visual reference
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.