When a system is compromised, attackers often try to disable auditing, in Windows 7;
modifications to the audit policy are recorded as entries of Event ID____________.
A.
4902
B.
3902
C.
4904
D.
3904
When a system is compromised, attackers often try to disable auditing, in Windows 7;
modifications to the audit policy are recorded as entries of Event ID____________.
When a system is compromised, attackers often try to disable auditing, in Windows 7;
modifications to the audit policy are recorded as entries of Event ID____________.
A.
4902
B.
3902
C.
4904
D.
3904
the correct answer is C https://technet.microsoft.com/en-us/library/dd772736(v=ws.10).aspx
Wrote 312-49v8 exam yesterday and passed with 90%. (The passing score now is 70%)
Got 150 multiple choice questions, and only one new question!
Main objects of the exam are: Digital Evidence, Computer Forensics Lab, Windows Forensics, Application Password Crackers and Investigating Web Attacks.
I used the valid 312-49v8 dumps from: https://tr.im/NaIQA (180q, 100% valid now!)
Good Luck!