Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GAQM Exam CFA-001 Topic 1 Question 102 Discussion

Actual exam question for GAQM's CFA-001 exam
Question #: 102
Topic #: 1
[All CFA-001 Questions]

When a system is compromised, attackers often try to disable auditing, in Windows 7; modifications to the audit policy are recorded as entries of Event ID____________.

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

Lera
13 days ago
Wait, isn't it the other way around? I thought 4904 was the right answer.
upvoted 0 times
...
Felicitas
16 days ago
Hmm, I was thinking it was 3904, but now I'm second-guessing myself.
upvoted 0 times
...
Grover
17 days ago
I'm not sure, but I think it's C) 4904. Can someone explain why it's not A) 4902?
upvoted 0 times
...
Kristine
18 days ago
I'm sure it's 4902, I've seen that in my security logs before.
upvoted 0 times
...
Alpha
22 days ago
I agree with Mira, because modifications to the audit policy are recorded as entries of Event ID 4902.
upvoted 0 times
...
Mira
25 days ago
I think the answer is A) 4902.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77