CompTIA Server+ SK0-005 Practice Question
While investigating slow authentication on a Windows Server 2022 domain controller, you discover that no new entries have been written to the Security event log since yesterday. When you open Event Viewer, the console shows the message "The Security log is full" and records Event ID 1104. The log's properties indicate a maximum size of 512 MB and the retention method "Do not overwrite events (Clear log manually)" is selected. Disk space on the system volume is still abundant.
Which underlying condition is MOST likely preventing the operating system from writing additional security events?
The Windows Event Log service is disabled in the Services console.
The server's CMOS battery has failed, so events cannot be time-stamped correctly.
Strict SMB signing is causing write failures when the system tries to commit log entries.
The Security event log has reached its configured maximum size and manual-clear retention is blocking further writes.