nerdexam
EC-Council

312-49 · Question #497

Company ABC has employed a firewall, IDS, Antivirus, Domain Controller, and SIEM. The company's domain controller goes down. From which system would you begin your investigation?

The correct answer is C. SIEM. A Security Information and Event Management (SIEM) system aggregates and correlates logs from all other security and infrastructure components - including the Domain Controller, Firewall, IDS, and Antivirus. Because the Domain Controller is already down, you cannot directly…

Submitted by khalil_dz· Apr 18, 2026Computer Forensics Investigation Process

Question

Company ABC has employed a firewall, IDS, Antivirus, Domain Controller, and SIEM. The company's domain controller goes down. From which system would you begin your investigation?

Options

  • ADomain Controller
  • BFirewall
  • CSIEM
  • DIDS

How the community answered

(54 responses)
  • A
    9% (5)
  • B
    2% (1)
  • C
    83% (45)
  • D
    6% (3)

Explanation

A Security Information and Event Management (SIEM) system aggregates and correlates logs from all other security and infrastructure components - including the Domain Controller, Firewall, IDS, and Antivirus. Because the Domain Controller is already down, you cannot directly query it for logs. The SIEM, however, will have ingested and stored its log data prior to the outage, making it the best starting point to reconstruct the timeline of events, identify the root cause, and correlate activity across the environment.

Topics

#SIEM#Incident Response#Log Management#Investigation Start Point

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice