nerdexam
Microsoft

70-663 · Question #157

A corporate environment includes an on-premise deployment of Exchange Server 2010 SP1 with stand-alone Edge Transport servers in a perimeter network. The company plans to move a subset of Exchange…

The correct answer is B. Add the security team members to the Organization Management, Recipient Management. Mailbox Audit Logging: By using mailbox audit logging, you can track logons to a mailbox, and also track what actions are taken while the user is logged on. When you enable mailbox audit logging for a mailbox, some actions performed by administrators and delegates are logged by…

Designing for Monitoring and Reporting

Question

A corporate environment includes an on-premise deployment of Exchange Server 2010 SP1 with stand-alone Edge Transport servers in a perimeter network. The company plans to move a subset of Exchange users to a cloud-based Exchange Server 2010 SP1 service. The security team has the following requirements:

  • Manage mailbox audit logging for the on-premise and cloud-based

Exchange servers.

  • Search message tracking logs for all on-premise Exchange servers.

You need to recommend a solution that meets the requirements. What should you recommend?

Options

  • AUse group policy to manage audit settings.
  • BAdd the security team members to the Organization Management, Recipient Management,
  • CUse group policy to manage audit settings.
  • DAdd the security team members to the Organization Management, Recipient Management,

How the community answered

(21 responses)
  • A
    14% (3)
  • B
    71% (15)
  • C
    5% (1)
  • D
    10% (2)

Explanation

Mailbox Audit Logging: By using mailbox audit logging, you can track logons to a mailbox, and also track what actions are taken while the user is logged on. When you enable mailbox audit logging for a mailbox, some actions performed by administrators and delegates are logged by default. None of the actions performed by the mailbox owner are logged. Auditing of mailbox owner actions can generate a large number of mailbox audit log entries. Therefore, this feature is disabled by To enable Mailbox Audit Logging use EMShell, Set-Mailbox -Identity "Ben Smith" -AuditEnabled $true To execute this command you have to be assigned with these roles: Search message tracking logs: A message tracking log is a detailed log of all message activity as messages are transferred to and from a Microsoft Exchange Server 2010-based computer that has the Hub Transport server role, the Mailbox server role, or the Edge Transport server role installed. You can use the Get-MessageTrackingLog cmdlet in the Exchange Management Shell and the Message Tracking tool in the Toolbox in the Exchange Management Console to search for entries in the message tracking logs by using specific search criteria. Local Administrators The Exchange Auditing log contains a record of audited events and the Event Viewer has an ACL that prevents typical users from clearing the event log. If a local administrator took ownership of the appropriate registry key, reset the CustomSD value, and then restarted the server, the administrator could clear the Exchange Auditing log.

Topics

#mailbox audit logging#message tracking#RBAC#hybrid monitoring

Community Discussion

No community discussion yet for this question.

Full 70-663 Practice