Which of the following Windows features is used to enable Security Auditing in Windows?
A.
Bitlocker
B.
Windows Firewall
C.
Local Group Policy Editor
D.
Windows Defender
The Answer Is:
C
This question includes an explanation.
Explanation:
To enable Security Auditing in Windows, the Local Group Policy Editor is used. This feature allows administrators to configure security policies and audit settings on a local computer. Here’s how you can enableSecurity Auditing using the Local Group Policy Editor:
Press Win + R, type gpedit.msc, and press Enter to open the Local Group Policy Editor.
Navigate to Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Audit Policy.
Here, you will find a list of audit policies that you can configure for both success and failure events.
By enabling these policies, you can specify which security-related events you want to audit, such as account logon events, object access, policy change, privilege use, and more.
[References: The process described above is aligned with the best practices and guidelines provided by Microsoft and other authoritative sources on Windows security auditing, such as:, Microsoft’s official documentation on Security Auditing1., Guides on how to enable Security Auditing in Active Directory environments2., Articles detailing the essentials of Windows event log security auditing3. These references are part of the learning resources for the EC-Council SOC Analyst course and provide comprehensive information on the subject., , Reference: https://resources.infosecinstitute.com/topic/how-to-audit-windows-10-application-logs/, ]
312-39 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"