nerdexam
CompTIA

SK0-004 · Question #237

A user reports that each day some files are deleted from the department share. The administrator needs to find who deleted these files. Which of the following actions should the administrator perform?

The correct answer is C. Enable audit object access and specify files and folders to monitor using Windows Explorer. Tracking file deletions requires enabling the 'Audit Object Access' policy and then configuring auditing on the specific files or folders through Windows Explorer's Security properties.

Security and disaster recovery

Question

A user reports that each day some files are deleted from the department share. The administrator needs to find who deleted these files. Which of the following actions should the administrator perform?

Options

  • AEnable audit object access and specify files and folders to monitor using Task Manager.
  • BEnable audit policy change and specify files and folders to monitor using Windows Explorer.
  • CEnable audit object access and specify files and folders to monitor using Windows Explorer.
  • DOpen Performance Monitor and monitor folder activity.

How the community answered

(40 responses)
  • A
    15% (6)
  • B
    5% (2)
  • C
    73% (29)
  • D
    8% (3)

Why each option

Tracking file deletions requires enabling the 'Audit Object Access' policy and then configuring auditing on the specific files or folders through Windows Explorer's Security properties.

AEnable audit object access and specify files and folders to monitor using Task Manager.

Task Manager monitors running processes and CPU/memory performance and cannot be used to configure file or folder auditing settings.

BEnable audit policy change and specify files and folders to monitor using Windows Explorer.

'Audit Policy Change' logs changes to the audit policy configuration itself, not file access or deletion events by users.

CEnable audit object access and specify files and folders to monitor using Windows Explorer.Correct

The 'Audit Object Access' policy in Local Security Policy or Group Policy enables Windows to log access events for securable objects such as files and folders. After enabling this policy, an administrator must open Windows Explorer, access the Security tab of the specific file or folder, and add an audit entry - this two-step process causes deletion events to be written to the Security event log with the responsible user's identity.

DOpen Performance Monitor and monitor folder activity.

Performance Monitor collects system performance metrics such as disk I/O counters and does not log file-level access events tied to specific user accounts.

Concept tested: Configuring audit object access for file and folder monitoring

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-file-system

Topics

#audit policy#object access auditing#file monitoring#Windows security

Community Discussion

No community discussion yet for this question.

Full SK0-004 Practice