SK0-004 · Question #237
A user reports that each day some files are deleted from the department share. The administrator needs to find who deleted these files. Which of the following actions should the administrator perform?
The correct answer is C. Enable audit object access and specify files and folders to monitor using Windows Explorer. Tracking file deletions requires enabling the 'Audit Object Access' policy and then configuring auditing on the specific files or folders through Windows Explorer's Security properties.
Question
A user reports that each day some files are deleted from the department share. The administrator needs to find who deleted these files. Which of the following actions should the administrator perform?
Options
- AEnable audit object access and specify files and folders to monitor using Task Manager.
- BEnable audit policy change and specify files and folders to monitor using Windows Explorer.
- CEnable audit object access and specify files and folders to monitor using Windows Explorer.
- DOpen Performance Monitor and monitor folder activity.
How the community answered
(40 responses)- A15% (6)
- B5% (2)
- C73% (29)
- D8% (3)
Why each option
Tracking file deletions requires enabling the 'Audit Object Access' policy and then configuring auditing on the specific files or folders through Windows Explorer's Security properties.
Task Manager monitors running processes and CPU/memory performance and cannot be used to configure file or folder auditing settings.
'Audit Policy Change' logs changes to the audit policy configuration itself, not file access or deletion events by users.
The 'Audit Object Access' policy in Local Security Policy or Group Policy enables Windows to log access events for securable objects such as files and folders. After enabling this policy, an administrator must open Windows Explorer, access the Security tab of the specific file or folder, and add an audit entry - this two-step process causes deletion events to be written to the Security event log with the responsible user's identity.
Performance Monitor collects system performance metrics such as disk I/O counters and does not log file-level access events tied to specific user accounts.
Concept tested: Configuring audit object access for file and folder monitoring
Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-file-system
Topics
Community Discussion
No community discussion yet for this question.