Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Logical Operations Exam CFR-210 Topic 5 Question 72 Discussion

Actual exam question for Logical Operations's CFR-210 exam
Question #: 72
Topic #: 5
[All CFR-210 Questions]

The incident response team needs to track which user last connected to a specific Windows domain controller. Which of the following is the BEST way to identify that specific user?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

Theola
6 days ago
Haha, good luck trying to check the user's computer event logs. That's just going to lead you on a wild goose chase. Domain controller logs all the way!
upvoted 0 times
...
Otis
9 days ago
I'm going with option D. Checking the Security Log on the domain controller is the best way to get the information we need. This is an incident response scenario, after all.
upvoted 0 times
...
Mike
12 days ago
I believe checking the Systems Event Log on the domain controller could also be helpful in identifying the specific user.
upvoted 0 times
...
Merilyn
13 days ago
The Security Log on the domain controller seems like the most logical choice to track the user's last connection. That's where the domain activity is recorded, right?
upvoted 0 times
...
Genevive
13 days ago
I agree with Taryn, checking the Security Log on the domain controller would provide the most accurate information.
upvoted 0 times
...
Taryn
21 days ago
I think the best way is to check the Security Log on the domain controller.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77