CHFI OS and Network Forensics Practice Question
A forensic analyst examining a Windows machine finds a suspicious service named 'SrvMon' installed. The System event log shows Event ID 7045 at the time of compromise. What does this event indicate?
⚠ Common exam trap
Many candidates confuse Event ID 7045 with security-related events (like logon or account creation) because they occur in the same timeframe, but 7045 is strictly a System log event for service installation, not a Security log event.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A service was installed
Event ID 7045 in the Windows System event log is specifically generated when a new service is installed on the system. The forensic analyst found a suspicious service named 'SrvMon', and the presence of this event at the time of compromise directly indicates that the service was installed, making option C correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A logon attempt failed
Why it's wrong here
Event ID 7045 is a System log event emitted by the Windows Service Control Manager when a new service is registered; it is unrelated to authentication failures. A failed logon attempt is recorded in the Security log as Event ID 4625, which includes the account name, workstation, source IP, and logon type. Therefore, seeing 7045 on a machine indicates service creation, not a failed logon.
- ✗
A user account was created
Why it's wrong here
Windows tracks account management events in the Security log, and the creation of a new user is Event ID 4720, not 7045. Event ID 7045 is written to the System log specifically by the Service Control Manager when a new service is installed, and it contains the binary path and service start mode. Since 4720 remains the correct marker for user creation, 7045 would be an incorrect interpretation.
- ✓
A service was installed
Why this is correct
Event ID 7045 is generated by the Service Control Manager (SCM) in the System log whenever a service is newly installed on a Windows machine, making it a reliable indicator of service installation. The event displays the service name, image path, service type, start type, and service account — details that help an analyst identify persistence mechanisms or malicious services. For example, a service pointing to a DLL in a user-writable Temp folder would be highly suspicious.
- ✗
A scheduled task was created
Why it's wrong here
Scheduled task creation is not logged as Event ID 7045; it appears in the Security log as Event ID 4698 when task audit logging is enabled, or in the Task Scheduler Operational log as Event ID 106. Event ID 7045, by contrast, is reserved exclusively by the Service Control Manager for new service installation and should not be confused with task scheduling. Thus, a system showing 7045 cannot be evidence of a scheduled task being created.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.