Centralized Logging with Windows

Centralized Logging with Windows

Assessment

Interactive Video

Computers

10th - 12th Grade

Practice Problem

Hard

Created by

Liam Anderson

FREE Resource

The video tutorial by Toby from Oine Security covers setting up a centralized logging system using Windows servers. It explains the importance of monitoring events for security purposes and demonstrates configuring a Windows server (DC10) to collect logs from another server (MS10). The tutorial includes detailed steps using PowerShell commands to enable remote event logging and verify the setup through the Windows Event Viewer. The video concludes with a review and questions about centralized logging management.

Read more

10 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is the primary purpose of a centralized logging server?

To enhance internet speed

To store all network data

To monitor and collect events from various network devices

To replace firewalls and routers

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which tool is commonly used for centralized logging in many use cases?

SIM tool

Firewall

Router

Antivirus software

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What command is used to enable the WinRM listener on dc10?

winrm quickconfig

Enable-PSRemoting

Start-Service

Enable-EventLog

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is the role of ms10 in the centralized logging setup?

It acts as the main server

It forwards logs to the centralized server

It replaces the centralized server

It monitors the centralized server

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which application is used on dc10 to collect logs from ms10?

Control Panel

Event Viewer

File Explorer

Task Manager

6.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What should be selected in Event Viewer to start collecting logs from ms10?

Create Task

Create Subscription

Create Event

Create Log

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

How can you verify that logs are being collected from ms10?

By checking the network speed

By viewing the logs in the Task Manager

By checking the forwarded events in Event Viewer

By restarting the server

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?