The incident response team needs to track which user last connected to a specific Windows domain controller. Which of the following is the BEST way to identify that specific user?
I'm pretty sure the answer is D. The domain controller is the central point of authentication, so that's where the user's connection details will be logged.
Haha, good luck trying to check the user's computer event logs. That's just going to lead you on a wild goose chase. Domain controller logs all the way!
I'm going with option D. Checking the Security Log on the domain controller is the best way to get the information we need. This is an incident response scenario, after all.
The Security Log on the domain controller seems like the most logical choice to track the user's last connection. That's where the domain activity is recorded, right?
Peggy
2 months agoFlorinda
24 days agoVincenza
25 days agoMargurite
29 days agoTheola
2 months agoNatalya
14 days agoMalcom
15 days agoMelda
19 days agoMalika
29 days agoOtis
2 months agoGolda
1 months agoTrinidad
1 months agoMike
2 months agoMerilyn
2 months agoGenevive
2 months agoTaryn
2 months ago