Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 716 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 716
Topic #: 1
[All 312-49v10 Questions]

A CHFI has been tasked to analyze Windows Security Logs in a highly complex and multi-layered security breach investigation. The breach involved an account creation, privilege escalation, and the installation of a service, all happening sequentially within a short duration. The investigator is required to retrieve a combination of Event IDs that would chronologically corroborate these events. Which combination of Event IDs should the investigator focus on?

  • A. Event ID 624, Event ID 4670, and Event ID 6011
  • B. Event ID 624, Event ID 500, and Event ID 7045
  • C. Event ID 4720, Event ID 4672, and Event ID 7045
  • D. Event ID 4720, Event ID 500, and Event ID 6011
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
aqeel1506
4 months ago
The other options do not accurately represent the sequence of events: A. Event ID 624 is related to trust anchoring, Event ID 4670 is related to a process exit, and Event ID 6011 is related to a BitLocker recovery password creation. B. Event ID 624 is related to trust anchoring, Event ID 500 is related to a process start, and Event ID 7045 is related to service installation (but the sequence doesn't match the breach events). D. Event ID 4720 is related to account creation, Event ID 500 is related to a process start (not relevant to the breach), and Event ID 6011 is related to BitLocker recovery password creation (not relevant to the breach).
upvoted 1 times
...
aqeel1506
4 months ago
For analyzing Windows Security Logs in a scenario involving account creation, privilege escalation, and service installation, the relevant Event IDs to focus on are: Event ID 4720: Indicates the creation of a new user account. Event ID 4672: Indicates the assignment of special privileges to a new or existing account (privilege escalation). Event ID 7045: Indicates the installation of a new service. So the correct combination of Event IDs to chronologically corroborate these events would be: C. Event ID 4720, Event ID 4672, and Event ID 7045
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...