Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

A forensic analyst examining a Windows machine finds a suspicious service named 'SrvMon' installed. The System event log shows Event ID 7045 at the time of compromise. What does this event indicate?

⚠ Common exam trap

Many candidates confuse Event ID 7045 with security-related events (like logon or account creation) because they occur in the same timeframe, but 7045 is strictly a System log event for service installation, not a Security log event.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A service was installed

Event ID 7045 in the Windows System event log is specifically generated when a new service is installed on the system. The forensic analyst found a suspicious service named 'SrvMon', and the presence of this event at the time of compromise directly indicates that the service was installed, making option C correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A logon attempt failed

    Why it's wrong here

    Event ID 7045 is a System log event emitted by the Windows Service Control Manager when a new service is registered; it is unrelated to authentication failures. A failed logon attempt is recorded in the Security log as Event ID 4625, which includes the account name, workstation, source IP, and logon type. Therefore, seeing 7045 on a machine indicates service creation, not a failed logon.

  • ✗

    A user account was created

    Why it's wrong here

    Windows tracks account management events in the Security log, and the creation of a new user is Event ID 4720, not 7045. Event ID 7045 is written to the System log specifically by the Service Control Manager when a new service is installed, and it contains the binary path and service start mode. Since 4720 remains the correct marker for user creation, 7045 would be an incorrect interpretation.

  • ✓

    A service was installed

    Why this is correct

    Event ID 7045 is generated by the Service Control Manager (SCM) in the System log whenever a service is newly installed on a Windows machine, making it a reliable indicator of service installation. The event displays the service name, image path, service type, start type, and service account — details that help an analyst identify persistence mechanisms or malicious services. For example, a service pointing to a DLL in a user-writable Temp folder would be highly suspicious.

  • ✗

    A scheduled task was created

    Why it's wrong here

    Scheduled task creation is not logged as Event ID 7045; it appears in the Security log as Event ID 4698 when task audit logging is enabled, or in the Task Scheduler Operational log as Event ID 106. Event ID 7045, by contrast, is reserved exclusively by the Service Control Manager for new service installation and should not be confused with task scheduling. Thus, a system showing 7045 cannot be evidence of a scheduled task being created.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.