312-49 Exam QuestionsBrowse all questions from this exam

312-49 Exam - Question 35


What method of computer forensics will allow you to trace all ever-established user accounts on a Windows 2000 sever the course of its lifetime?

Show Answer
Correct Answer: D

To trace all user accounts that have ever been established on a Windows 2000 server over its lifetime, you would need to review the Security Identifiers (SIDs) in the Registry. Each user account on a Windows system is assigned a unique SID, which is stored in the Registry. By examining these SIDs, you can identify all user accounts that have been created on the system.

Discussion

9 comments
Sign in to comment
PetOption: D
Jun 15, 2019

Answer shd be D. review of SIDs in the Registry

haymathsOption: D
Aug 19, 2019

Answer is D. Option C is totally out of it

ireenOption: D
Aug 25, 2019

Answer should be D. As user account are assigned a unique SID and SID are not reused.

ZeroDayOption: D
May 7, 2020

The answere is definitely The review of SIDs in the Reg. D

fhramkeOption: D
Jun 18, 2022

Answer shd be D. review of SIDs in the Registry

jordy55Option: D
Nov 17, 2022

Defintly D

simbaiOption: D
Jun 13, 2023

The Security Identifier (SID) is a unique identifier assigned to each user account in Windows. By reviewing the SIDs in the Registry, a forensic investigator can trace all ever-established user accounts on a Windows 2000 server over the course of its lifetime

tej0nOption: D
Sep 14, 2023

SID registry identifies all history user account in Windows.

Bennoli13Option: D
Jun 13, 2024

To trace all user accounts that have ever been established on a Windows 2000 server over its lifetime, you would need to review the Security Identifiers (SIDs) in the Registry. Each user account on a Windows system is assigned a unique SID, which is stored in the Registry. By examining these SIDs, you can identify all user accounts that have been created on the system. Therefore, the correct answer is: D. review of SIDs in the Registry