exam questions

Exam MD-100 All Questions

View all questions & answers for the MD-100 exam

Exam MD-100 topic 5 question 14 discussion

Actual exam question from Microsoft's MD-100
Question #: 14
Topic #: 5
[All MD-100 Questions]

You have 20 computers that run Windows 10.
You configure all the computers to forward all the events from all the logs to a computer named Computer1 that runs Windows 10.
When you sign in to Computer1, you cannot see any security events from other computers. You can see all the other forwarded events from the other computers.
You need to ensure that the security events are forwarded to Computer1.
What should you do?

  • A. On each computer, run wecutil qc /q.
  • B. On each computer, add the NETWORK SERVICE account to the Event Log Readers group.
  • C. On each computer, run winrm qc ג€"q.
  • D. On Computer1, add the account of Computer1 to the Event Log Readers group.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mendel
Highly Voted 5 years, 7 months ago
Isn't B correct? From the link you supplied: Add the Network Service account to the built-in Event Log Readers security group. This allows reading from secured event channel, such as the security event channel. No mention about putting the computer object in this group.
upvoted 13 times
KornienkoBoris
5 years, 6 months ago
yep, seems like truth appendix D Appendix D - Minimum GPO for WEF Client configuration Add the Network Service account to the built-in Event Log Readers security group. This allows reading from secured event channel, such as the security event channel.
upvoted 2 times
...
...
forummj
Highly Voted 4 years, 6 months ago
Answer: B "Note: Many of the event logs in Windows Server already provide the Network Service account access to the common event logs like Application and System. But the account is not given access to the Security event log and other custom event logs." https://adamtheautomator.com/windows-event-log-forwarding/
upvoted 8 times
...
xeni66
Most Recent 2 years, 2 months ago
Selected Answer: C
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-r2-and-2008/cc748890(v=ws.10)
upvoted 1 times
...
NoursBear
2 years, 2 months ago
I have just tested this, I have given my normal user account the Event Log Reader membership then connected to eventviewer remotely to the client and I was able to read all logs. When I removed the membership and did the same exercise I get the error that I don't have access. I answered this wrong at the test yesterday. Howecer something is not quite right with the question because since the user could read all the other logs except securty, it no longer makes sense.
upvoted 1 times
...
williamlamata
2 years, 2 months ago
B. On each computer, add the NETWORK SERVICE account to the Event Log Readers group. Explanation: By default, only the security event logs are not available to non-administrative users, so adding the NETWORK SERVICE account to the Event Log Readers group is enough to forward the security events to Computer1.
upvoted 1 times
...
drhousedk
2 years, 4 months ago
Selected Answer: B
https://docs.microsoft.com/en-us/advanced-threat-analytics/configure-event-collection
upvoted 1 times
...
Crataeis
2 years, 6 months ago
Selected Answer: B
B= Correct.
upvoted 1 times
...
Vonpink
2 years, 7 months ago
Selected Answer: B
https://docs.microsoft.com/en-us/advanced-threat-analytics/configure-event-collection
upvoted 1 times
...
Adyz
3 years ago
Answer B: https://docs.microsoft.com/en-us/advanced-threat-analytics/configure-event-collection
upvoted 1 times
...
PChi
3 years, 1 month ago
I would say given answer is correct. computers have already been set up and are forwarding events. By default, standard users can access system, application and setup logs. But in order to access security logs, you have to add that object to the event readers security group. Network Service would not be the best option due to the fact that all other logs have been forwarded other than security events. Therefore, the needed services to receive event and deliver subscriptions have been properly configured. https://docs.microsoft.com/en-us/windows/win32/services/networkservice-account
upvoted 2 times
PChi
3 years, 1 month ago
"By default, standard users can access system, application and setup logs"- I GOT THIS SPECIFIC SENTENCE FROM MEASUREUP.COM exam prep for MD 100!
upvoted 2 times
...
...
devilcried
3 years, 2 months ago
Selected Answer: B
I will go for B
upvoted 1 times
...
stevenk16
3 years, 2 months ago
Answer: B
upvoted 1 times
...
fchahin
4 years, 5 months ago
The winrm quickconfig command (or the abbreviated version winrm qc ) performs these operations. Starts the WinRM service, and sets the service startup type to auto-start. Configures a listener for the ports that send and receive WS-Management protocol messages using either HTTP or HTTPS on any IP address I believe that Answer ( D ) is the correct with 99.9%
upvoted 1 times
...
Anthony_2770
4 years, 7 months ago
Additional Notes : If you cannot connect to a remote host, verify that the service on the remote host is running and is accepting requests by running the following command on the remote host: winrm quickconfig This command analyzes and configures the WinRM service " /q is for quite mode - If present, quickconfig will not prompt for confirmation. Configure the Windows Event Collector Service The following syntax is used to configure the Windows Event Collector service to ensure event subscriptions can be created and sustained through computer restarts. This includes the following procedure: To configure the Windows Event Collector service 1. Enable the ForwardedEvents channel if it is disabled. 2. Delay the start of the Windows Event Collector service. 3. Start the Windows Event Collector service if it is not running. syntaxCopy wecutil { qc | quick-config } /q:VALUE Parameters **/q:**VALUE A value that determines whether the quick-config command will prompt for confirmation. VALUE can be true or false. If VALUE is true, then the command will prompt for confirmation. The default value is false.
upvoted 3 times
Anthony_2770
4 years, 5 months ago
Forgot to add B Add the Network Service account to the built-in Event Log Readers security group. This allows reading from secured event channel, such as the security event channel.
upvoted 6 times
...
...
CharlesM
4 years, 8 months ago
In The link Explanation, search to "Appendix D" : " Add the Network Service account to the built-in Event Log Readers security group. This allows reading from secured event channel, such as the security event channel." B must be Correct for me.
upvoted 4 times
...
Mizzjhaded
4 years, 10 months ago
On the question it says "You can see all the other forwarded events from the other computers." so that's assuming the computer1 is already added to Event Log Readers group. For me the answer on this is B.
upvoted 8 times
...
Redders
5 years, 4 months ago
D is correct - https://www.petri.com/configure-event-log-forwarding-windows-server-2012-r2 Before a collector can access the Event Log, you will need to add the collector’s computer account to the Event Log Readers group.
upvoted 5 times
Forsmark
5 years, 2 months ago
Read further down in the link you sent. It says that B is correct.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago