312-49v10 Exam QuestionsBrowse all questions from this exam

312-49v10 Exam - Question 539


A CHFI professional is investigating a data breach in a Windows 10 system. The initial analysis revealed some alterations in the system event logs. As part of the investigation, the professional uses the ‘wevtutil’ command-line tool. The command ‘wevtutil gl Security’ was executed, but the results seemed abnormal. Which of the following could be a plausible reason for this outcome?

Show Answer
Correct Answer: D

The 'wevtutil' command is designed to interact with the Windows Event Log service and retrieve event log data, including data from the security log. The command 'wevtutil gl Security' is valid and should provide detailed information about the security log. If the results seemed abnormal, a plausible reason could be that the EVTX file storing the Security log was corrupted or tampered with. Such corruption or tampering can cause the command to produce abnormal output.

Discussion

2 comments
Sign in to comment
ElbOption: D
Apr 27, 2024

D < https://www.gigasheet.com/post/online-evtx-parser-and-viewer#:~:text=What%20Are%20EVTX%20Files%20Anyway,format%20used%20in%20Windows%20XP.

ElbOption: D
May 29, 2024

Windows 10 store event logs in EVTX file format and are based on XML (Extension Markup Language) wevtutil command can be used to retrieve information about event logs and publishers that is not readily apparent via the Event Viewer user interface.