Courseiva
mediumMatching

Windows Event Log Indicators of Successful Compromise

Match each Windows event log type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Logs success/failure audit events

Logs operating system events

Logs events from applications

Logs installation events

Logs events forwarded from other computers

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Application: Records events generated by software programs.

In Windows Event Viewer, the main logs are Application (software events), Security (audit events), Setup (installation events), System (system component events), and Forwarded Events (remote logs). Common confusions include mixing Application and System logs, or Security with Setup.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Application: Records events generated by software programs.

    Why this is correct

    Application logs capture events from applications, such as crashes or errors.

  • ✗

    Application: Logs events related to system hardware failures.

    Why it's wrong here

    Incorrect — hardware failures are logged in the System log, not Application.

  • ✗

    Security: Logs application installation events.

    Why it's wrong here

    Incorrect — application installations are logged in the Setup log, not Security.

  • ✓

    Security: Logs security-related events such as logon attempts.

    Why this is correct

    Security events include authentication, resource access, and policy changes.

  • ✓

    System: Records events related to system components like drivers.

    Why this is correct

    System logs contain events from system services, drivers, and hardware.

  • ✓

    Forwarded Events: Contains events collected from remote computers.

    Why this is correct

    Forwarded Events is used to aggregate logs from multiple machines.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 200-201

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which two Sysmon Event IDs are most commonly associated with code injection techniques?

easy
  • A.Event ID 3 (Network connect)
  • ✓ B.Event ID 8 (CreateRemoteThread)
  • C.Event ID 1 (Process creation)
  • D.Event ID 7 (Image loaded)
  • ✓ E.Event ID 10 (ProcessAccess)

Why B: Event ID 8 (CreateRemoteThread) is correct because it is logged when a process creates a thread in another process, which is the classic Sysmon signature of remote thread injection (e.g., CreateRemoteThread or NtCreateThreadEx targeting a foreign process). Event ID 10 (ProcessAccess) is correct because it records a process opening a handle to another process, capturing the GrantedAccess mask (such as PROCESS_VM_WRITE and PROCESS_CREATE_THREAD) that injection techniques require to write shellcode and start execution in the target. Event ID 3 (Network connect) only logs outbound TCP/UDP connections and does not reflect in-memory injection behavior. Event ID 1 (Process creation) documents new process launches and may show a suspicious parent, but it does not capture cross-process memory or thread manipulation. Event ID 7 (Image loaded) records DLL/module loads and can hint at injected modules, yet it is not the primary indicator of the injection act itself.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.