CHFI OS and Network Forensics Practice Question
An analyst suspects that an attacker used a web shell to execute commands on a Windows web server. Which Windows event ID should the analyst look for to detect service installation that may have been used for persistence?
⚠ Common exam trap
Many candidates confuse event IDs for logon events (4624, 4648) or user creation (4720) with service installation, because they associate persistence broadly with any authentication or account change rather than the specific service creation event.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
7045
Event ID 7045 is logged by the Windows Service Control Manager when a new service is installed on the system. An attacker who gains a web shell often installs a malicious service to maintain persistence, and this event captures the service name, binary path, and service type, making it the primary forensic artifact to detect such activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
7045
Why this is correct
Event ID 7045 indicates that a new service was installed on the Windows system. When an attacker exploits a web shell, they often escalate privileges or establish persistence by installing a malicious service that executes a payload at system startup. Therefore, a 7045 event appearing alongside web shell traffic is a strong indicator of post-exploitation activity, making it the most relevant option.
- ✗
4624
Why it's wrong here
Event ID 4624 logs every successful authentication to the host, including interactive, network, and remote logons. Web shells typically execute within the existing web server process (e.g., w3wp.exe) and do not initiate a distinct logon session; they run under the web application pool's identity. Hence, 4624 is too generic and not a specific or reliable artifact of web shell usage.
- ✗
4648
Why it's wrong here
Event ID 4648 records explicit credential logon attempts where a user supplies alternate credentials via RunAs or credential delegation. A web shell operates by receiving HTTP requests and executing commands under the already-authenticated web server context, without invoking any separate credential validation. Therefore, 4648 is not generated by web shell activity and instead points to a different form of credential abuse, making it incorrect.
- ✗
4720
Why it's wrong here
Event ID 4720 indicates the creation of a new user account, a persistence technique often employed after initial compromise. Installing a web shell does not require nor typically trigger user account creation; the shell simply provides remote command execution through the web server's existing security context. While a threat actor might later create an account for persistent access, 4720 is not a direct indicator of web shell exploitation.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.