Courseiva
OS and Network Forensics →easyMultiple Choice

CHFI OS and Network Forensics Practice Question

A forensic examiner is analyzing a Windows system and wants to determine the last time a specific user logged on interactively. Which Windows Event Log artifact should the examiner review?

⚠ Common exam trap

Many exam-takers confuse logon events with logoff events or system events, and overlooking that Logon Type 2 specifically denotes an interactive logon at the console.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security event log, Event ID 4624 with Logon Type 2.

Interactive logons are recorded in the Security event log as Event ID 4624 with Logon Type 2. This event includes the timestamp, user account, and other details necessary to determine when the logon occurred. Other event IDs and logs either record different activities or are not related to user logons, making them unsuitable for this purpose.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Application event log, Event ID 1000 indicating an application error.

    Why it's wrong here

    Event ID 1000 in the Application log indicates a program crash or application error. It has no relation to user logon activity. The Application log records events generated by applications, not security-related logons. Therefore, it is not useful for determining interactive logon times.

  • ✓

    Security event log, Event ID 4624 with Logon Type 2.

    Why this is correct

    Event ID 4624 is logged for successful logons, and Logon Type 2 indicates an interactive logon at the console. This directly answers the question of when a user last logged on interactively. The event includes the date and time, user account, and other details. It is the primary artifact for interactive logon history in Windows Security logs.

  • ✗

    Security event log, Event ID 4634 indicating a logoff.

    Why it's wrong here

    Event ID 4634 indicates a logoff event, not a logon. While it can show when a session ended, it does not directly provide the logon time. The question asks for the last interactive logon, so reviewing logon events (4624) is more appropriate. Logoff events are complementary but not the primary artifact for logon time.

  • ✗

    System event log, Event ID 6005 indicating the Event Log service started.

    Why it's wrong here

    Event ID 6005 in the System log indicates that the Event Log service started, which typically occurs at system boot. It does not record user logons. While it can help establish system uptime, it does not provide information about interactive user logons. The Security log is the correct source for logon events.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.