
GIAC Security Essentials
Domain 4Objective 7
Windows Automation, Auditing, and Forensics GSEC Practice Questions (Page 9)
Part of the Endpoint and Platform Security domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~30–51 in this domain), expect 3–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 41–45
- 41
Which Windows audit policy category would you enable to track successful and failed attempts to log on to a Windows system?
Select an answer first - 42
Which tool or feature in Windows allows you to create custom queries to filter event logs based on specific criteria such as event ID or source?
Select an answer first - 43
A forensic examiner needs to create a forensic image of a Windows system's hard drive. The examiner wants to ensure the image is an exact copy and that the original drive is not modified. Which tool and method should be used?
Select an answer first - 44
During an incident response, you must create a forensic image of a Windows laptop's hard drive. The laptop is running and the user cannot shut it down. Which acquisition method best preserves evidentiary integrity?
Select an answer first - 45
In NTFS, what is the Master File Table (MFT) primarily used for?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.