exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 413 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 413
Topic #: 1
[All 312-49v10 Questions]

Shane, a forensic specialist, is investigating an ongoing attack on a MySQL database server hosted on a Windows machine with SID `WIN-ABCDE12345F.`
Which of the following log file will help Shane in tracking all the client connections and activities performed on the database server?

  • A. WIN-ABCDE12345F.err
  • B. WIN-ABCDE12345F-bin.n
  • C. WIN-ABCDE12345F.pid
  • D. WIN-ABCDE12345F.log
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
044f354
6 days, 13 hours ago
Selected Answer: B
B - the binary log provides the detailed logging required for forensic investigations into database attacks. ----- A. WIN-ABCDE12345F.err (Error Log) This file logs error messages, startup, and shutdown events. B. [CORRECT] WIN-ABCDE12345F-bin.n (Binary Log) The binary log is a critical component of MySQL. It records all changes made to the database, such as queries that modify data (INSERT, UPDATE, DELETE). It also logs client connections and session activity, which makes it invaluable for forensic analysis. C. WIN-ABCDE12345F.pid (Process ID File) This file contains the process ID of the running MySQL server. D. WIN-ABCDE12345F.log (General Log) The general log records every query and command executed on the server, including connection and disconnection information.
upvoted 1 times
...
Cisco103
2 weeks ago
Selected Answer: D
that easy log file is .log
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago