Courseiva
OS and Network Forensics →easyMultiple Choice

CHFI OS and Network Forensics Practice Question

A security analyst reviews Windows Security Event Log and finds multiple Event ID 4625 entries for a single user account within a few seconds. What does this pattern MOST likely indicate?

⚠ Common exam trap

EC-CHFI often tests the distinction between Event ID 4625 (failed logon) and Event ID 4624 (successful logon), and the trap here is that candidates may confuse the event ID numbers or misinterpret a burst of failures as a successful logon or account creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute-force password attack

Event ID 4625 is a Windows Security log event that records failed logon attempts. When multiple 4625 events appear for the same user account within a few seconds, it indicates a high volume of authentication failures in a short time window, which is the classic signature of a brute-force password attack. The rapid succession of failures rules out accidental mistypes and points to an automated or manual attempt to guess the password.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Service installation

    Why it's wrong here

    Service installation is recorded under Event ID 7045 in the System event log, which logs when a new service is installed on the system. In contrast, Event ID 4625 is a Security log entry that specifically captures failed logon attempts. Since the analyst is reviewing Security events with ID 4625, these cannot indicate service installation, which uses a completely different event ID and log source.

  • ✗

    Account creation

    Why it's wrong here

    User account creation is tracked as Event ID 4720 in the Security log, which fires when a new user object is created in Active Directory or on a local system. Event ID 4625, on the other hand, is generated only after an authentication failure occurs, meaning the user attempted to log on but was denied. Thus, repeated 4625 entries do not reflect account provisioning events but instead indicate failed login activity.

  • ✓

    Brute-force password attack

    Why this is correct

    Multiple rapid Event ID 4625 entries in the Windows Security log are a hallmark indicator of a brute-force password attack. Each 4625 represents a failed logon attempt, and when an attacker submits numerous password guesses for the same account or from the same source IP in a short time, the log reveals a high volume of these failures. Analysts can correlate timestamps, source addresses, and target usernames to distinguish this systematic guessing from legitimate but occasional mistyped passwords.

  • ✗

    Successful logon by the user

    Why it's wrong here

    Event ID 4625 is explicitly defined as a failed logon attempt, so it cannot represent a successful authentication. Successful logons in Windows are logged as Event ID 4624, which records the user, logon type, and source. The presence of 4625 events therefore indicates attempts that did not succeed, making the conclusion of a successful logon by the user incorrect.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.