exam questions

Exam 70-744 All Questions

View all questions & answers for the 70-744 exam

Exam 70-744 topic 1 question 43 discussion

Actual exam question from Microsoft's 70-744
Question #: 43
Topic #: 1
[All 70-744 Questions]

Your network contains an Active Directory domain named contoso.com. The domain contains five file servers that run Windows Server 2016.
You have an organizational unit (OU) named Finance that contains all of the servers.
You create a Group Policy object (GPO) and link the GPO to the Finance OU.
You need to ensure that when a user in the finance department deletes a file from a file server, the event is logged. The solution must log only users who have a manager attribute of Ben Smith.
Which audit policy setting should you configure in the GPO?

  • A. File system in Global Object Access Auditing
  • B. Audit Detailed File Share
  • C. Audit Other Account Logon Events
  • D. Audit File System in Object Access
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
References:
https://technet.microsoft.com/en-us/library/cc976403.aspx

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ArchBishop
Highly Voted 5 years, 6 months ago
I am convinced that the answer is A. To log events based on Attributes of a User you need Object Expression-Based Auditing: https://www.rootusers.com/create-expression-based-audit-policies/
upvoted 7 times
...
itguru
Highly Voted 5 years, 5 months ago
A is the right answer. You will find a good explanation here: https://www.petri.com/configure-global-object-access-auditing-windows-server
upvoted 6 times
...
SamsOtro
Most Recent 4 years, 5 months ago
Fairly certain correct answer is: A. File system in Global Object Access Auditing
upvoted 4 times
...
Kamikazekiller
4 years, 9 months ago
Answer is wrong, correct answer is: A. File system in Global Object Access Auditing
upvoted 3 times
...
A. File system in Global Object Access Auditing
upvoted 3 times
...
Ario
5 years, 1 month ago
A is correct
upvoted 3 times
...
coleman
5 years, 2 months ago
the correct answer should be A. File system in Global Object Access Auditing
upvoted 3 times
...
Njamajama
5 years, 3 months ago
C is correct for me.
upvoted 2 times
alex_p
5 years, 3 months ago
absolutely not!
upvoted 3 times
...
...
ArchBishop
5 years, 6 months ago
D is not a good answer either. Advanced Audit Policy Configuration > Object Access > Audit File System will certainly audit Object Manipulation Events, including File Deletion, as the question suggests. HOWEVER, This option does not allow the same "configure" option, within the File System Properties of that Policy, that would allow for the Expression-Based Auditing that the question is looking to accomplish: (i.e. Attribute: Manager == Ben Smith) As far as I can tell, this option is only available in: Advanced Audit Policy Configuration > Global Object Access Auditing > File System Please correct me if there is another Group Policy that allows for Expression-Based Auditing.
upvoted 2 times
...
thomasemr
5 years, 8 months ago
I believe it is option B https://docs.microsoft.com/pt-br/windows/security/threat-protection/auditing/audit-detailed-file-share
upvoted 1 times
ArchBishop
5 years, 6 months ago
B would not be a good answer for this scenario. While it will log an Event every time that a File or Folder is accessed, It will not log an event BASED on the attributes of the User; which must have the Manager Attribute set to Ben Smith.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago