Courseiva
Host-Based Analysis →hardMultiple Choice

200-201 Host-Based Analysis Practice Question

During an incident response engagement, an analyst is examining a Windows Server 2019 host that is suspected of being compromised. The analyst wants to determine which user accounts were used to log on interactively to the console in the last 24 hours. Which Windows artifact should the analyst query to obtain this information?

⚠ Common exam trap

The trap here is mixing up logon type numbers, especially selecting Logon Type 3 for network access or using 4634, which records logoffs rather than successful logons.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Event ID 4624 with Logon Type 2

Successful interactive logons at the console are recorded as Security Event ID 4624 with Logon Type 2. Filtering for that combination and the last 24 hours gives the analyst the specific accounts used for interactive console access on the server, which is exactly the requested scope.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security Event ID 4672 with Logon Type 2

    Why it's wrong here

    Security Event ID 4672 is logged when special privileges are assigned to a new logon, such as for administrator accounts. While it often accompanies elevated logons, it does not enumerate interactive console logons and may appear for non-interactive administrative sessions, making it unsuitable for this query.

  • ✗

    Security Event ID 4624 with Logon Type 3

    Why it's wrong here

    Logon Type 3 indicates a network logon, such as access to a shared folder or remote registry, not an interactive console session. Selecting it would return accounts that connected over the network rather than the users who physically logged on at the server console, so it does not answer the question.

  • ✗

    Security Event ID 4634 with Logon Type 2

    Why it's wrong here

    Security Event ID 4634 records logoff events rather than logons, and although it includes a logon type field, it marks the end of a session. Using it would identify when sessions ended instead of which accounts initiated interactive console logons, so it is not the correct artifact.

  • ✓

    Security Event ID 4624 with Logon Type 2

    Why this is correct

    Security Event ID 4624 records successful logons, and Logon Type 2 specifically indicates an interactive logon at the console. Filtering 4624 events by Logon Type 2 and the desired time window gives the analyst exactly the list of accounts used for interactive console access on the server.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.