Soru

Zorluk: Çok zorWindows Administrative and System Management Tools

A senior systems administrator is reviewing operational management workflows across Windows 11 Enterprise workstations to enforce administrative compliance and performance baselining. Match each administrative requirement on the left with the most appropriate native Windows management snap-in or utility on the right.

  • Capturing continuous system metrics (such as Processor Queue Length and Available MBytes memory) into a log file over a scheduled 48-hour evaluation period.Performance Monitor (perfmon.msc)
  • Reconfiguring the service execution account identity for a custom background worker application from Local System to a low-privilege domain account.Services MMC Snap-in (services.msc)
  • Configuring an automated execution sequence that launches an administrative recovery script immediately upon the logging of a specific Security Audit failure Event ID.Task Scheduler (taskschd.msc)
  • Auditing active remote SMB connections and disconnecting specific locked file handles hosted on a peer-to-peer workstation share.Computer Management Shared Folders (compmgmt.msc)

Cevap

The administrative requirements map to the utilities as follows: 48-hour baseline counter logging maps to Performance Monitor; service account identity configuration maps to the Services MMC snap-in; event-triggered automated script execution maps to Task Scheduler; and SMB active session/open file management maps to Computer Management Shared Folders.
Each administrative tool serves a distinct management function: Performance Monitor captures historical baselines via Data Collector Sets; the Services snap-in manages service logon security contexts; Task Scheduler handles event-driven task automation; and Computer Management (Shared Folders) controls network user sessions and file locks on shared directories.

Adım Adım Çözüm

1
Evaluate the requirement for extended baseline performance logging over 48 hours
Identify that logging performance counters continuously to binary or text log files requires a User-Defined Data Collector Set, which is built into Performance Monitor (perfmon.msc).
Task Manager and Resource Monitor only provide real-time/short-term telemetry and cannot run background scheduled counter logs over multi-day periods.
2
Evaluate the requirement to change service execution credentials
Identify that modifying the account identity (e.g., specifying a dedicated service account instead of Local System) is managed via the 'Log On' tab in the Services MMC snap-in (services.msc).
Service startup parameters, recovery actions, and logon security contexts are configured directly inside the Services console.
3
Evaluate the requirement for automated script execution triggered by specific Event IDs
Identify that configuring scheduled or event-driven task execution based on log entries is performed within Task Scheduler (taskschd.msc).
Task Scheduler handles task triggers based on system events, user logons, or recurring schedules.
4
Evaluate the requirement to audit SMB connections and force-close locked open files on a local share
Identify that viewing active SMB sessions and terminating open file handles hosted locally is accomplished via Computer Management (compmgmt.msc) under System Tools > Shared Folders.
The Shared Folders node in Computer Management provides granular management of Shares, Sessions, and Open Files.

Anahtar Kavram

Windows Administrative Tool Capabilities and Management Scenarios
Bu soruyu puanla