GCIH • Practice Test 18
Free GCIH practice test — 15 questions with explanations. Set 18. No signup required.
A GCIH incident responder is conducting a forensic investigation of a compromised Windows system. The responder needs to determine which user accounts were used to log on to the system and whether any unauthorized access occurred. Which Windows event log should the responder examine to find successful and failed logon attempts?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.