QuestionQ85
Forensics Investigation and Malware AnalysisDavid is a SOC analyst at an institution and is responsible for monitoring the security of critical infrastructure. During routine system monitoring, he identifies several unauthorized applications running on a high-privilege Windows server that only a restricted set of users can access. These applications were not included in any approved software deployment, and no users have acknowledged installing them. He observes that the installations took place outside business hours, and the affected server logs show possible system-configuration changes at approximately the same time. He suspects an attacker may have exploited misconfigurations or obtained unauthorized access to install malicious software. Which log file should he review to establish when and how these installations took place?
- A Security Event log
- B Setup Event log
- C Application Event log
- D System Event log
Community Discussion