Quiz 5 Question 18 of 20

An incident response team discovers that an attacker has been present in the network for 6 months. The attacker used a valid domain administrator account. Which forensic artifact is most useful for establishing a timeline of the attacker's activities within Active Directory?

Select an answer to reveal the explanation.

Motivation