Question 13 of 13
You manage a single domain named widgets.com.
One day you notice that a trust relationship you have established with another forest has changed. You
reconfigure the trust, but you want to be able to identify if this change happens again in the future. You want
to configure auditing to track this event.
Which auditing category should you enable?
0 System events
0 Logon events
0 Process tracking events
@ Policy change events
0 Object access events
Explanation
Audit policy change events to track changes to user rights, trust relationships, IPsec and Kerberos policies, or audit
policies.
Object access auditing tracks access to files, folders, or printers. Process tracking auditing records actions taken by
applications. Process tracking auditing is used mainly for program debugging and tracking. System events auditing
tracks system shutdown, restart, or the starting of system services. It also tracks events that affect security or the security
log. Logon auditing tracks logon or log off on the local system, or when a network connection is made to a system.
Objectives
Objectives for MS 70-41 0:
602 Configure security policies
References
LabSim for Windows Server Pro: Install and Configure, Section 8.4.
[Questions.exm MULTIPLE CHOICE [149]]