You have a computer that runs Windows 7.
You need to record when an incoming connection is allowed through Windows firewall.
What should you do?
A.
In Local Group Policy, modify the audit policy.
B.
In Local Group Policy, modify the system audit policy.
C.
From the Windows Firewall with Advanced Security properties, set the logging settings to Log
successful connections.
D.
From the Windows Firewall with Advanced Security properties, set the Data Protection (Quick
Mode) IPSec settings to Advanced.
Explanation:
Customize Logging Settings for a Firewall Profile
Windows Firewall with Advanced Security can be configured to log events that indicate the
successes and failures of its processes. The logging settings involve two groups of settings: settings
for the log file itself and settings that determine which events the file will record. The settings can be
configured separately for each of the firewall profiles. You can specify where the log file will be
created, how big the file can grow, and whether you want the log file to record information about
dropped packets, successful connections, or both.
Log successful connections
Use this option to log when Windows Firewall with Advanced Security allows an inbound connection.
The log records why and when the connection was formed. Look for entries with the word ALLOW in
the action column of the log.