On a Windows Server you need a rolling text log that records both dropped packets and successful connections for the active firewall profile, written to the default path, with a maximum size of 32 MB. What should you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: In Windows Defender Firewall with Advanced Security, open the Properties of the active profile and set Log dropped packets = Yes and Log successful connections = Yes; set the log size to 32768 KB. Review %SystemRoot%\System32\LogFiles\Firewall\pfirewall.log..
Why this is the answer
The correct option directly addresses the requirements for a rolling text log of dropped packets and successful connections for the active firewall profile. Windows Defender Firewall with Advanced Security allows you to configure logging directly within the properties of each firewall profile (Domain, Private, Public). Setting "Log dropped packets" and "Log successful connections" to Yes enables the desired logging, and specifying the log size in KB (32 MB = 32768 KB) meets the size requirement. The default log path is indeed %SystemRoot%\System32\LogFiles\Firewall\pfirewall.log. Enabling the Microsoft-Windows-WFP/Operational event log records events in an .etl file, which is not a rolling text log and requires specific tools to view. Enabling audit policies records events to the security event log, not a dedicated firewall text log. Running netsh wfp capture start creates a network trace, which is a different type of diagnostic output than the requested firewall activity log.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed