Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 312-49 Exam - Topic 10 Question 95 Discussion

What method of computer forensics will allow you to trace all ever-established user accounts on a Windows 2000 sever the course of its lifetime?
C) comparison of MD5 checksums
A) forensic duplication of hard drive
B) analysis of volatile data
D) review of SIDs in the Registry

Eccouncil 312-49 Exam - Topic 10 Question 95 Discussion

Actual exam question for Eccouncil's 312-49 exam
Question #: 95
Topic #: 10
[All 312-49 Questions]

What method of computer forensics will allow you to trace all ever-established user accounts on a Windows 2000 sever the course of its lifetime?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Sage
2 days ago
I thought Windows 2000 was outdated for this stuff!
upvoted 0 times
...
Shonda
7 days ago
A) forensic duplication could also help, right?
upvoted 0 times
...
Julio
12 days ago
Wait, are we sure that’s the only method?
upvoted 0 times
...
Merilyn
18 days ago
Totally agree, that's the way to go!
upvoted 0 times
...
Danica
23 days ago
Gotta be D) review of SIDs in the Registry.
upvoted 0 times
...
Heike
28 days ago
Not sure if that’s enough info, sounds too simple.
upvoted 0 times
...
Dana
1 month ago
Totally agree with D, it’s the best way to track user accounts.
upvoted 0 times
...
Rodrigo
1 month ago
Wait, can you really trace all accounts just from the Registry?
upvoted 0 times
...
Karrie
1 month ago
I think A is more reliable for a full picture.
upvoted 0 times
...
Fausto
2 months ago
Gotta go with D, reviewing SIDs is key!
upvoted 0 times
...
Margot
2 months ago
I keep getting confused between SIDs and checksums; I think SIDs are the way to go for user accounts, but I need to double-check that.
upvoted 0 times
...
Sabra
2 months ago
I practiced a similar question, and I feel like volatile data analysis is more about current sessions rather than historical accounts.
upvoted 0 times
...
Eden
2 months ago
I’m not entirely sure, but I remember something about forensic duplication being more about data recovery than tracing accounts.
upvoted 0 times
...
Pete
4 months ago
I think the answer might be D, reviewing SIDs in the Registry, since SIDs are tied to user accounts.
upvoted 0 times
...

Save Cancel