Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 687 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 687
Topic #: 1
[All 312-49v10 Questions]

A large corporation has recently undergone a cyberattack. The forensic analyst finds suspicious activities in the Windows Event logs during the investigation. The analyst notes that a specific service on the machine has been frequently starting and stopping during the time of the attack. What event IDs should the analyst look for in the System log to confirm this suspicious behavior?

  • A. Event ID 7035 and Event ID 7036
  • B. Event ID 1 and Event ID 7035
  • C. Event ID 7031 and Event ID 7032
  • D. Event ID 7036 and Event ID 7037
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
aqeel1506
4 months ago
The forensic analyst should look for the following event IDs in the System log to confirm suspicious behavior related to a service frequently starting and stopping: A. Event ID 7035 and Event ID 7036 Event ID 7035: This event ID indicates that a service control manager has requested a service to start or stop. Event ID 7036: This event ID indicates that a service has changed its state (started, stopped, etc.). These events are crucial for tracking the status changes of services on a Windows system and can help identify unusual or suspicious behavior.
upvoted 1 times
...
jingu_bingo
5 months, 3 weeks ago
Selected Answer: A
Event ID 7035: This event ID indicates that the service control manager has sent a start or stop control to a service. Event ID 7036: This event ID indicates that a service has entered a state, such as running or stopped. revealed to me in a vision.
upvoted 1 times
...
Elb
6 months ago
A > For an example if host A had his service state changed from running to stopped then it will generate an event id 7035/7036 on the windows event log on the Windows Server.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...