Courseiva
Host-Based Analysis →mediumMultiple Choice

200-201 Host-Based Analysis Practice Question

A SOC analyst is reviewing a Windows 10 endpoint after a suspected compromise. They need to determine which user account was responsible for a specific process that was launched shortly before the alert. Which Windows artifact directly records the user account associated with process creation events and should be queried using Windows Event Log?

⚠ Common exam trap

Many candidates confuse process creation auditing with logon auditing, so candidates pick 4625 or 7045 when the question specifically asks for the user tied to a launched process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Event ID 4688 with the associated user account field

When process creation auditing is enabled, Windows logs Security Event ID 4688 for each new process, and the event includes the subject user name that initiated it. Correlating the process name and timestamp in 4688 with the alert time lets the analyst attribute the suspicious process to a specific user account, which is exactly what is needed here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security Event ID 4625 with the Account Name field

    Why it's wrong here

    Security Event ID 4625 indicates a failed logon attempt and includes the account name used in that failed authentication. It logs authentication failures rather than process creation, so it cannot show which user account launched a specific process on the endpoint after the compromise.

  • ✗

    System Event ID 7045 with the ServiceName field

    Why it's wrong here

    System Event ID 7045 records that a new service was installed on the system, including the service name and image path. It does not capture general process creation events nor does it reliably associate a process with the interactive user account, so it cannot answer which user launched the suspicious process.

  • ✗

    Application Event ID 1000 with the Faulting application name field

    Why it's wrong here

    Application Event ID 1000 is a Windows Error Reporting event triggered when an application crashes. It contains faulting module and application path details but is unrelated to normal process creation and does not record the user account that launched the process, making it unsuitable for this attribution task.

  • ✓

    Security Event ID 4688 with the associated user account field

    Why this is correct

    Security Event ID 4688 is generated when a new process is created and, when process creation auditing is enabled, includes the 'SubjectUserName' and 'TargetUserName' fields that identify the account that initiated the process. This directly answers the analyst's need to attribute process execution to a specific user account on the endpoint.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.