Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 312-49 Exam - Topic 10 Question 95 Discussion

What method of computer forensics will allow you to trace all ever-established user accounts on a Windows 2000 sever the course of its lifetime?
C) comparison of MD5 checksums
A) forensic duplication of hard drive
B) analysis of volatile data
D) review of SIDs in the Registry

Eccouncil 312-49 Exam - Topic 10 Question 95 Discussion

Actual exam question for Eccouncil's 312-49 exam
Question #: 95
Topic #: 10
[All 312-49 Questions]

What method of computer forensics will allow you to trace all ever-established user accounts on a Windows 2000 sever the course of its lifetime?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Fausto
5 hours ago
Gotta go with D, reviewing SIDs is key!
upvoted 0 times
...
Margot
5 days ago
I keep getting confused between SIDs and checksums; I think SIDs are the way to go for user accounts, but I need to double-check that.
upvoted 0 times
...
Sabra
11 days ago
I practiced a similar question, and I feel like volatile data analysis is more about current sessions rather than historical accounts.
upvoted 0 times
...
Eden
16 days ago
I’m not entirely sure, but I remember something about forensic duplication being more about data recovery than tracing accounts.
upvoted 0 times
...
Pete
2 months ago
I think the answer might be D, reviewing SIDs in the Registry, since SIDs are tied to user accounts.
upvoted 0 times
...

Save Cancel