Search Header Logo

Security Pro Section Win Logging 12.4.6 quiz

Authored by Angel Martinez

Computers

Professional Development

Used 1+ times

Security Pro Section Win Logging 12.4.6 quiz
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

9 questions

Show all answers

1.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

Which two types of service accounts must you use to set up event subscriptions?

Specific user service account

Default machine account

Collector computer account

Network server machine account

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

By default, events received from the source computers in Event Subscription are saved in which log?

Application log

System log

Security log

Forwarded Events log

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

You set up Event Subscription, but you are getting an overwhelming amount of events recorded. What should you do?

Choose the correct subscription type

Define a filter

Use the Runtime Status link

Use the default machine account

4.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

Which of the following are required to configure Event Subscription for event forwarding? (Select three.)

Create a Windows firewall exception for HTTP or HTTPS on all source computers.

Start Windows Event Collector service on collector computer.

Start Windows Remote Management service on both the source and collector computers.

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

You are configuring a source-initiated subscription on the collector computer in Event Viewer. Which of the following do you need to specify?

computer group is for a source-initiated subscription.

Selecting a computer would be for the collector-initiated subscription.

The Forwarded Events log is selected, not the System log.

Content filtering is a strategy to keep employees from accessing unauthorized content on the web.

6.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

For some reason, your source computers are not communicating properly with the collector. Which tool would you use to verify communications?

Runtime Status to verify communications after you have created a subscription

wecutil qc command would simply run the Windows Event Collector service.

winrm qc -q command would initiate the Windows Remote Management service

Event Viewer System log would not verify current communications

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

For source-initiated subscriptions, which tool do you use to configure event forwarding?

Group Policy

service account only provides permissions to run properly

Event forwarding settings for source-initiated subscriptions are unavailable in Event Viewer

Filters define what is collected. They do not enable and configure event forwarding.

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?