nerdexam
EC-CouncilEC-Council

312-49 · Question #84

312-49 Question #84: Real Exam Question with Answer & Explanation

Sign in or unlock 312-49 to reveal the answer and full explanation for question #84. The question stem and answer options stay visible for context.

Submitted by javi_es· Apr 18, 2026Computer Forensics Investigation Process

Question

Windows Security Event Log contains records of login/logout activity or other security- related events specified by the system's audit policy. What does event ID 531 in Windows Security Event Log indicates?

Options

  • AA user successfully logged on to a computer
  • BThe logon attempt was made with an unknown user name or a known user name with a bad
  • CAn attempt was made to log on with the user account outside of the allowed time
  • DA logon attempt was made using a disabled account

Unlock 312-49 to see the answer

You've previewed enough free 312-49 questions. Unlock 312-49 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Windows Security Event Log#Event ID 531#Logon failures#Security auditing
Full 312-49 PracticeBrowse All 312-49 Questions