Which of the following statements describe WMI polling mode for FSSO collector agent? (Choose two.)
A. The collector agent does not need to search any security event logs.
B. WMI polling can increase bandwidth usage with large networks.
C. The NetSessionEnum function is used to track user logoffs.
D. The collector agent uses a Windows API to query DCs for user logins.
AD
A,D
Event log using WMI polling: WMI is a Windows API to get system information from a Windows server, CA is a
WMI client and sends WMI queries for user logon events to DC, which in this case is a WMI server. Main
advantage in this mode is that CA does not need to search security event logs on DC for user logon events,
instead, DC returns all requested logon events via WMI. This also reduces network load between CA and DC.
AD.