312-49V10 Web TestEngine demo

Exit VCEDump 312-49V10 EC-Council Certified Computer Hacking Forensic Investigator (V10)
Question 2 of 100
0% complete
Q2 Single choice

A forensics investigator is studying the Event ID logs on a domain controller for a corporation, following a suspected security breach. He notices that a domain user account was created, then modified, and then added to a group in a very short span of time. The investigator realizes that he must cross-verify the audit policies on the local system to understand if any changes were made to it.

Assuming that the investigator has the correct audit policy settings, which of the following Event IDs should he focus on?

Sign in to mark questions

Sign in to save marked questions and return to this demo.

Sign in