Courseiva

GSEC Windows Automation and Auditing Practice Question

You are auditing a Windows server and need to identify which user accounts have recently utilized elevated privileges. Which specific Event ID should you prioritize in the Security log?

⚠ Common exam trap

Test-takers often look for standard successful logon IDs like 4624 instead of checking for special privilege assignment events during administrative sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Event ID 4672

Event ID 4672 is generated immediately upon a successful logon when a user is assigned special privileges, such as SeDebugPrivilege or SeBackupPrivilege. Auditing this ID allows administrators to track the lifecycle of administrative access, effectively mapping privilege escalation to specific user sessions. Monitoring this is critical for detecting potential account compromise or unauthorized administrative activity within the Windows environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Event ID 4624

    Why it's wrong here

    Event ID 4624 records a successful logon, but it does not specifically distinguish between standard user sessions and those with administrative privileges. While useful for general traffic analysis, it lacks the specificity needed to pinpoint instances where elevated rights were granted to a session.

  • ✓

    Event ID 4672

    Why this is correct

    This event explicitly indicates that a logon session has been assigned special privileges. It is the definitive audit log entry for identifying administrative access at the moment of login, providing a clear trail for security analysts monitoring for unauthorized privilege usage.

  • ✗

    Event ID 4720

    Why it's wrong here

    Event ID 4720 signifies that a new user account has been created within the local security database. While account creation is a sensitive event, it does not confirm that the user has successfully logged in or utilized elevated privileges during their session.

  • ✗

    Event ID 1102

    Why it's wrong here

    Event ID 1102 indicates that the security audit log has been cleared by an administrator. While this is a high-priority security event that warrants investigation, it does not provide visibility into which users have exercised elevated privileges prior to the log clearing event.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.