nerdexam
EC-CouncilEC-Council

312-49 · Question #123

312-49 Question #123: Real Exam Question with Answer & Explanation

The correct answer is A: Net sessions. The 'net sessions' command on Windows displays information about active SMB/NetBIOS sessions connected to the local machine, including the username, client IP address, idle time, and the type of client (e.g., Windows version). This is valuable in forensic investigations to identi

Submitted by jaden.t· Apr 18, 2026Network Forensics

Question

Which of the following commands shows you the username and IP address used to access the system via a remote login session and the Type of client from which they are accessing the system?

Options

  • ANet sessions
  • BNet file
  • CNet config
  • DNet share

Explanation

The 'net sessions' command on Windows displays information about active SMB/NetBIOS sessions connected to the local machine, including the username, client IP address, idle time, and the type of client (e.g., Windows version). This is valuable in forensic investigations to identify who is remotely connected. 'Net file' lists open shared files. 'Net config' shows configuration of server or workstation services. 'Net share' lists shared resources on the machine. Only 'net sessions' provides the remote user identity and client information needed for session auditing.

Topics

#Windows commands#Network sessions#Remote login#System access monitoring

Community Discussion

No community discussion yet for this question.

Full 312-49 PracticeBrowse All 312-49 Questions