The incident response team needs to track which user last connected to a specific Windows domain controller. Which of the following is the BEST way to identify that specific user?
I'm pretty sure the answer is D. The domain controller is the central point of authentication, so that's where the user's connection details will be logged.
Haha, good luck trying to check the user's computer event logs. That's just going to lead you on a wild goose chase. Domain controller logs all the way!
I'm going with option D. Checking the Security Log on the domain controller is the best way to get the information we need. This is an incident response scenario, after all.
The Security Log on the domain controller seems like the most logical choice to track the user's last connection. That's where the domain activity is recorded, right?
Peggy
1 months agoFlorinda
8 days agoVincenza
9 days agoMargurite
13 days agoTheola
1 months agoMelda
3 days agoMalika
13 days agoOtis
2 months agoGolda
27 days agoTrinidad
29 days agoMike
2 months agoMerilyn
2 months agoGenevive
2 months agoTaryn
2 months ago