Courseiva
Host-Based Analysis →mediumMultiple Select

200-201 Host-Based Analysis Practice Question

A security analyst is investigating a Windows workstation that experienced a series of failed logon attempts followed by a successful logon. Which TWO Windows Event IDs should the analyst examine to understand this activity?

⚠ Common exam trap

Many exam-takers confuse credential-validation events (4776 on the DC, 4648 for explicit credentials) with the endpoint-side success/failure events (4624/4625) that actually answer the question about a workstation's logon sequence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

4624 - An account was successfully logged on

The scenario describes failed logon attempts followed by a successful logon, so the analyst needs the events that directly record those two outcomes. Option A (4624 - An account was successfully logged on) is correct because Event ID 4624 is generated in the Security log whenever a logon succeeds, capturing details such as the account name, logon type, and source workstation that confirm the successful authentication. Option E (4625 - An account failed to log on) is correct because Event ID 4625 is logged for each failed authentication attempt and includes the failure reason, account name, and logon type, which together with 4624 reveals the brute-force-then-success pattern. Option B (4720 - A user account was created) is not relevant because it records account creation, not authentication activity. Option C (4648 - A logon was attempted using explicit credentials) is not relevant because it logs use of alternate credentials (e.g., RunAs), not the failed/successful logon sequence described. Option D (4776 - The domain controller attempted to validate the credentials for an account) is not relevant because it is a credential-validation event on a domain controller, not the workstation logon success/failure events the analyst needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    4624 - An account was successfully logged on

    Why this is correct

    Event ID 4624 records the successful logon that terminated the brute-force sequence, satisfying the stem's requirement to examine the outcome following repeated failures. Its logon type field distinguishes interactive, network, and remote access, letting the analyst confirm whether the successful authentication came from the same source as the failed attempts.

  • ✗

    4720 - A user account was created

    Why it's wrong here

    Event 4720 records account creation, which is unrelated to failed-then-successful logon sequences; the relevant IDs are 4625 and 4624. It is tempting because it is a genuine security-relevant account event, and it would be the correct choice when investigating unauthorised account provisioning or persistence rather than brute-force authentication activity.

  • ✗

    4648 - A logon was attempted using explicit credentials

    Why it's wrong here

    Event 4648 logs explicit-credential use, such as runas or scheduled tasks, not the interactive failed-then-successful logon sequence; 4625 and 4624 cover that. It is tempting because it is authentication-related, and it would be the correct choice when investigating lateral movement or processes using alternate credentials.

  • ✗

    4776 - The domain controller attempted to validate the credentials for an account

    Why it's wrong here

    Event 4776 appears on domain controllers validating credentials, not on the workstation itself, so it does not capture the local failed-then-successful logon pattern. It is tempting because it genuinely records authentication attempts, and it would be correct when investigating credential validation against a domain controller rather than local workstation logon events.

  • ✓

    4625 - An account failed to log on

    Why this is correct

    Event ID 4625 records each failed logon attempt, capturing the account name, source workstation and failure reason. Examining these entries establishes the brute-force or password-guessing pattern described in the stem before the eventual successful authentication.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.