nerdexam
EC-Council

312-49V11 · Question #167

A CHFI professional is investigating a data breach in a Windows 10 system. The initial analysis revealed some alterations in the system event logs. As part of the investigation, the professional…

The correct answer is D. The EVTX file storing the Security log was corrupted or tampered with. wevtutil gl is a valid command and works with EVTX. If results are abnormal in a context where logs may have been altered, a corrupted or tampered EVTX Security log file is a strong explanation. This fits the scenario's premise of event log manipulation.

Windows Forensics

Question

A CHFI professional is investigating a data breach in a Windows 10 system. The initial analysis revealed some alterations in the system event logs. As part of the investigation, the professional uses the 'wevtutil' command-line tool. The command 'wevtutil gl Security' was executed, but the results seemed abnormal. Which of the following could be a plausible reason for this outcome?

Options

  • AThe command 'wevtutil gl Security' does not exist in the 'wevtutil' command set
  • BThe 'wevtutil' command cannot retrieve data from XML-based EVTX file format
  • CThe Event Log service was temporarily unresponsive or down
  • DThe EVTX file storing the Security log was corrupted or tampered with

How the community answered

(52 responses)
  • A
    13% (7)
  • B
    4% (2)
  • C
    10% (5)
  • D
    73% (38)

Explanation

wevtutil gl is a valid command and works with EVTX. If results are abnormal in a context where logs may have been altered, a corrupted or tampered EVTX Security log file is a strong explanation. This fits the scenario's premise of event log manipulation.

Topics

#wevtutil#event log tampering#EVTX file#Windows security logs

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice