312-49V11 · Question #167
A CHFI professional is investigating a data breach in a Windows 10 system. The initial analysis revealed some alterations in the system event logs. As part of the investigation, the professional…
The correct answer is D. The EVTX file storing the Security log was corrupted or tampered with. wevtutil gl is a valid command and works with EVTX. If results are abnormal in a context where logs may have been altered, a corrupted or tampered EVTX Security log file is a strong explanation. This fits the scenario's premise of event log manipulation.
Question
A CHFI professional is investigating a data breach in a Windows 10 system. The initial analysis revealed some alterations in the system event logs. As part of the investigation, the professional uses the 'wevtutil' command-line tool. The command 'wevtutil gl Security' was executed, but the results seemed abnormal. Which of the following could be a plausible reason for this outcome?
Options
- AThe command 'wevtutil gl Security' does not exist in the 'wevtutil' command set
- BThe 'wevtutil' command cannot retrieve data from XML-based EVTX file format
- CThe Event Log service was temporarily unresponsive or down
- DThe EVTX file storing the Security log was corrupted or tampered with
How the community answered
(52 responses)- A13% (7)
- B4% (2)
- C10% (5)
- D73% (38)
Explanation
wevtutil gl is a valid command and works with EVTX. If results are abnormal in a context where logs may have been altered, a corrupted or tampered EVTX Security log file is a strong explanation. This fits the scenario's premise of event log manipulation.
Topics
Community Discussion
No community discussion yet for this question.