nerdexam
EC-Council

312-49 · Question #476

Operating System logs are most beneficial for Identifying or Investigating suspicious activities involving a particular host. Which of the following Operating System logs contains information about…

The correct answer is A. Event logs. Event logs (e.g., Windows Event Log) record operational actions performed by OS components such as system startups/shutdowns, driver loads, service starts/stops, and application errors. They are the primary source for investigating host-level OS activity. Audit logs…

Submitted by ahmad_uae· Apr 18, 2026Disk Forensics

Question

Operating System logs are most beneficial for Identifying or Investigating suspicious activities involving a particular host. Which of the following Operating System logs contains information about operational actions performed by OS components?

Options

  • AEvent logs
  • BAudit logs
  • CFirewall logs
  • DIDS logs

How the community answered

(28 responses)
  • A
    93% (26)
  • B
    4% (1)
  • C
    4% (1)

Explanation

Event logs (e.g., Windows Event Log) record operational actions performed by OS components such as system startups/shutdowns, driver loads, service starts/stops, and application errors. They are the primary source for investigating host-level OS activity. Audit logs specifically track security-related events like login successes/failures and privilege use. Firewall logs track network traffic rules. IDS logs record detected intrusion signatures - neither of these is generated by OS components for general operational activity.

Topics

#OS logs#Event logs#Log analysis#Host forensics

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice