This event's sub category will vary depending on type of object. This event will be Audit Success or Audit Failure depending on whether the user account under which the account is running has the requested permissions or not.
file or folder), this is the first event recorded when an application attempts to access the object in such a way that matches the audit policy defined for that object in terms of who is requesting the access and what type of access is being requested. (it appears that two subcategories must be enabled, Handle Manipulation and one other such as File System or Registry depending on what type of object you are auditing.) When you enable auditing on an object (e.g. This event is logged by multiple subcategories as indicated above.