The incident response team needs to track which user last connected to a specific Windows domain controller. Which of the following is the BEST way to identify that specific user?
I'm pretty sure the answer is D. The domain controller is the central point of authentication, so that's where the user's connection details will be logged.
Haha, good luck trying to check the user's computer event logs. That's just going to lead you on a wild goose chase. Domain controller logs all the way!
I'm going with option D. Checking the Security Log on the domain controller is the best way to get the information we need. This is an incident response scenario, after all.
The Security Log on the domain controller seems like the most logical choice to track the user's last connection. That's where the domain activity is recorded, right?
Peggy
3 months agoFlorinda
2 months agoVincenza
2 months agoMargurite
2 months agoTheola
3 months agoNatalya
1 months agoMalcom
1 months agoMelda
2 months agoMalika
2 months agoOtis
3 months agoGolda
2 months agoTrinidad
2 months agoMike
3 months agoMerilyn
3 months agoGenevive
3 months agoTaryn
3 months ago