
GIAC Security Essentials
Domain 4Objective 7
Windows Automation, Auditing, and Forensics GSEC Practice Questions (Page 5)
Part of the Endpoint and Platform Security domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~30–51 in this domain), expect 3–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 21–25
- 21
A security analyst needs to detect attempts to access a sensitive file share. The analyst wants to enable auditing that will generate events when users try to read or modify files in that share. Which audit policy configuration should be applied?
Select an answer first - 22
What is the primary purpose of hashing a forensic image after acquisition?
Select an answer first - 23
Which approach best combines automation and forensic tools to streamline audit reporting in a Windows environment?
Select an answer first - 24
A security team needs to collect security event logs from 50 Windows servers every hour and generate a daily summary report. The team wants to automate this process with minimal manual effort. Which approach is most effective?
Select an answer first - 25
What is the primary purpose of acquiring a memory dump from a Windows system during an incident response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.