All client computers on your company network run Windows 7. A software application that monitors
Internet usage is installed on each of the computers. You plan to collect all Critical and Error events
generated by the application and review them on your computer. You perform the following tasks
on your computer:
• Create an event subscription by using Event Viewer.
• Create a query filter and select Critical and Error events from the Application event log.
You need to ensure that the following requirements are met:
• Only Critical and Error events from the Application event log are forwarded to your
computer.
• The Application event log can be viewed from your computer and the computers that
generated the errors.
What should you do first?
A.
Set the Subscription type property to Collector initiated by using a Windows Remote Shell Group
Policy.
B.
Set the Subscription type property to Source initiated by using a Windows Remote Management
Service Group Policy.
C.
Set the Subscription type and source computers property to Source computer initiated by using a
Windows Remote Shell Group Policy.
D.
Set the Subscription type and source computers property to Collector initiated by using a
Windows Remote Management Client Group Policy.
Explanation:
http://msdn.microsoft.com/en-us/library/windows/desktop/bb870973(v=vs.85).aspx
on the client PCs, run the winrm (remote management) quickconfig command, and on the collecting PC (server), run the wecutil qc command. Hence the answer is B “source computer is initiated with winrm group policy.”