nerdexam
EC-Council

312-49V11 · Question #76

In event correlation, two types are discussed: Same-Platform, where a single OS is used throughout (e.g., Microsoft Windows), and Cross-Platform, where different OS and hardware are employed (e.g…

The correct answer is B. Utilizing Windows servers and Linux-based firewalls. Event correlation in CHFI v11 is a critical investigative technique used to reconstruct attack timelines by analyzing and correlating events from multiple log sources. The CHFI blueprint clearly distinguishes between Same-Platform Correlation and Cross-Platform Correlation…

Computer Forensics Investigation Process

Question

In event correlation, two types are discussed: Same-Platform, where a single OS is used throughout (e.g., Microsoft Windows), and Cross-Platform, where different OS and hardware are employed (e.g., Windows clients with a Linux firewall). In Cross-Platform Correlation, which scenario best illustrates its application?

Options

  • AImplementing uniform software versions throughout the network
  • BUtilizing Windows servers and Linux-based firewalls
  • CUsing Linux-based servers exclusively
  • DEmploying different antivirus software across devices

How the community answered

(40 responses)
  • A
    8% (3)
  • B
    75% (30)
  • C
    3% (1)
  • D
    15% (6)

Explanation

Event correlation in CHFI v11 is a critical investigative technique used to reconstruct attack timelines by analyzing and correlating events from multiple log sources. The CHFI blueprint clearly distinguishes between Same-Platform Correlation and Cross-Platform Correlation under the domain of Image/Evidence Examination and Event Correlation. Cross-Platform Correlation applies when an investigation involves heterogeneous environments, meaning different operating systems, hardware platforms, or network devices are involved in the incident. A common real-world example--explicitly referenced in CHFI training--is an enterprise environment where Windows-based client systems or servers interact with Linux-based infrastructure components such as firewalls, IDS/IPS devices, or proxies. In such cases, investigators must correlate Windows Event Logs with Linux syslogs, firewall logs, and network device records to build a unified timeline of attacker activity. Option B correctly reflects this scenario by describing the use of Windows servers alongside Linux-based firewalls, which is a textbook example of Cross-Platform Correlation. Option A relates to standardization, not correlation. Option C represents a single-platform environment, and Option D refers to security tooling diversity rather than operating system or platform diversity.

Topics

#event correlation#cross-platform correlation#log analysis#SIEM

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice