SSCP · Question #1174
Which of the following are NT Audit events? (Choose all that apply)
The correct answer is A. Logon and Logoff B. Use of User Rights C. Security Policy Change. NT Audit events include significant security activities like user logon/logoff, the use of special user rights, and changes to system security policies.
Question
Which of the following are NT Audit events? (Choose all that apply)
Options
- ALogon and Logoff
- BUse of User Rights
- CSecurity Policy Change
- DRegistry Tracking
- EAll of choices are correct
How the community answered
(34 responses)- A91% (31)
- D3% (1)
- E6% (2)
Why each option
NT Audit events include significant security activities like user logon/logoff, the use of special user rights, and changes to system security policies.
Logon and Logoff events track user authentication attempts, both successful and failed, which is a fundamental security audit category.
Use of User Rights refers to auditing when specific privileges (like 'Take ownership of files' or 'Shut down the system') are exercised, providing insight into administrative actions.
Security Policy Change events record modifications to security settings, audit policies, or user rights assignments, which are critical for detecting unauthorized configuration changes.
While specific registry object access can be audited under 'Object Access', 'Registry Tracking' is not a distinct, high-level NT Audit event category in the same manner as the others.
This is incorrect because 'Registry Tracking' is not a primary, distinct NT audit event category.
Concept tested: Windows NT Audit event categories
Source: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/audit-policy-recommendations
Topics
Community Discussion
No community discussion yet for this question.