nerdexam
EC-Council

312-49 · Question #44

Computer security logs contain information about the events occurring within an organization's systems and networks. Application and Web server log files are useful in detecting web attacks. The sourc

The correct answer is A. Analyzing log files. Analyzing log files is the correct method for determining the source, nature, and time of a web attack on a compromised system. Web and application server logs record details such as IP addresses, timestamps, HTTP methods, requested URLs, and response codes - all of which help re

Submitted by tyler.j· Apr 18, 2026Computer Forensics Investigation Process

Question

Computer security logs contain information about the events occurring within an organization's systems and networks. Application and Web server log files are useful in detecting web attacks. The source, nature, and time of the attack can be determined by _________of the compromised system.

Options

  • AAnalyzing log files
  • BAnalyzing SAM file
  • CAnalyzing rainbow tables
  • DAnalyzing hard disk boot records

How the community answered

(44 responses)
  • A
    86% (38)
  • B
    5% (2)
  • C
    7% (3)
  • D
    2% (1)

Explanation

Analyzing log files is the correct method for determining the source, nature, and time of a web attack on a compromised system. Web and application server logs record details such as IP addresses, timestamps, HTTP methods, requested URLs, and response codes - all of which help reconstruct an attack timeline. The SAM file stores local account credentials, rainbow tables are used for password cracking, and hard disk boot records relate to system startup - none of these are relevant to tracing web attacks.

Topics

#Log analysis#Web server logs#Incident detection#Digital evidence

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice