You must audit the following in your domain: new user creations (4720), account lockouts (4740), and failed logons (4625). Additionally, you need to detect attempts to modify objects within the ‘Service Accounts’ OU. All domain controllers run Windows Server 2019. Which two configurations should you implement?
Choose an answer
Tap an option to check your answer.
Correct answer: On the Default Domain Controllers Policy, enable Advanced Audit Policy Configuration: Audit Account Management (Success) and Audit Logon (Failure)., On the ‘Service Accounts’ OU, add a SACL to audit Write all properties and Create/Delete child objects, capturing Directory Service Access events..
Why this is the answer
To audit new user creations (4720) and account lockouts (4740), you need to enable "Audit Account Management (Success)" under Advanced Audit Policy Configuration on the Default Domain Controllers Policy. Failed logons (4625) are captured by enabling "Audit Logon (Failure)." These settings apply to all domain controllers. To detect modifications to objects within the 'Service Accounts' OU, a System Access Control List (SACL) is required. This SACL should be configured on the OU to audit "Write all properties" and "Create/Delete child objects" for "Directory Service Access" events, as these actions indicate object modification. "Enable only the ‘Directory Service Changes’ audit subcategory" is insufficient as it won't capture all required events like failed logons. "Enable legacy Audit Policy" is outdated and less granular than advanced policies, and disabling advanced processing is counterproductive. "Enable Object Access auditing only on member servers" is incorrect because object modifications within Active Directory occur on domain controllers, not typically on member servers.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed