The incident response team needs to track which user last connected to a specific Windows domain controller. Which of the following is the BEST way to identify that specific user?
I'm going with option D. Checking the Security Log on the domain controller is the best way to get the information we need. This is an incident response scenario, after all.
The Security Log on the domain controller seems like the most logical choice to track the user's last connection. That's where the domain activity is recorded, right?
Otis
1 hours agoMike
3 days agoMerilyn
4 days agoGenevive
4 days agoTaryn
12 days ago