A company has Windows 8.1 client computers. All user data is stored locally. Each data file
has a system access control list (SACL).
You need to ensure that an event is generated when a user modifies a local file.
Which audit policy setting should you configure?
A.
Audit process tracking
B.
Audit policy change
C.
Audit object access
D.
Audit privilege use
“an event is generated when a user modifies a local file.”
this means you need to keep track of object access.