Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

A security analyst reviews Windows Security event logs and finds Event ID 4625 with Logon Type 10. What does this indicate?

⚠ Common exam trap

Watch out — candidates often confuse Logon Type 10 with Logon Type 2 (interactive) or Logon Type 3 (network), failing to recognize that Type 10 is specifically for remote interactive (RDP) logons, and that Event ID 4625 always indicates failure, not success.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Failed remote interactive logon (e.g., RDP)

Event ID 4625 with Logon Type 10 specifically indicates a failed Remote Interactive logon attempt, which is characteristic of Remote Desktop Protocol (RDP) connections. Logon Type 10 is defined in Windows security auditing as 'RemoteInteractive' and is triggered when an authentication attempt fails over a remote desktop session, typically using RDP (port 3389). This event is critical for detecting brute-force or unauthorized RDP access attempts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Failed remote interactive logon (e.g., RDP)

    Why this is correct

    Event ID 4625 is the Windows security event for failed authentication, and Logon Type 10 (RemoteInteractive) is assigned specifically when the attempt occurs via a remote interactive protocol such as RDP. A 4625 event with Logon Type 10 therefore precisely indicates a failed remote interactive logon, commonly seen in RDP brute-force attacks. The combination of the failure code (4625) and the remote interactive logon type (10) leaves no ambiguity about the attempt's outcome and origin.

  • ✗

    Failed service logon attempt

    Why it's wrong here

    Service logon attempts use Logon Type 5 (Service), which is initiated by the Service Control Manager when a service starts, not by a remote interactive session. Event ID 4625 with Logon Type 10 is a failed remote interactive logon, so it does not correspond to a service logon attempt. Even though 4625 indicates failure, the logon type field definitively rules out Type 5, making this option incorrect.

  • ✗

    Successful network logon

    Why it's wrong here

    Event ID 4625 is exclusively a failure event; successful logons generate Event ID 4624 with a Success Audit keyword. Additionally, network logons that access resources such as file shares or named pipes use Logon Type 3 (Network), not Type 10. A successful network logon would therefore produce a 4624 event with Logon Type 3, so this option is wrong on both the event ID and the logon type.

  • ✗

    Successful local logon

    Why it's wrong here

    A successful local logon would generate Event ID 4624, not 4625, because 4625 is reserved for failed authentication attempts. Logon Type 10 (RemoteInteractive) is used for remote desktop sessions, whereas a physical console logon uses Logon Type 2 (Interactive). Thus, this option incorrectly identifies both the success/failure status and the local vs. remote nature of the logon.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.