Detecting Brute-Force Attacks via Windows Event ID 4625
A security analyst is reviewing Windows Security Event Logs and notices multiple Event ID 4625 entries for a single user account within a short time frame. What does this MOST likely indicate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Brute-force password guessing attack
Event ID 4625 indicates a failed logon attempt. Multiple failures in a short time suggest a brute-force attack against the user account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Brute-force password guessing attack
Why this is correct
Event ID 4625 is the Windows Security log event for a failed logon attempt. When dozens or hundreds of these events occur from the same source IP or user account within a short window, it strongly indicates a brute-force password guessing attack. Analysts should correlate Sub Status codes (e.g., 0xC000006A for bad password) and Logon Type (e.g., 2 interactive, 3 network) to confirm automated guessing. The rapid repetition of failures with varying passwords is the classic signature of this attack.
- ✗
Service installation
Why it's wrong here
Service installation is not represented by Event ID 4625; it is logged as Event ID 7045 in the System log, not the Security log. Event 7045 records the service name, image path, start type, and service type when a new service is installed. Without such a System event or an associated 7045 entry, service installation cannot be inferred from a series of failed logon events. Therefore, this option is incorrect because the supplied evidence is solely failed logon audit events.
- ✗
Account lockout policy change
Why it's wrong here
Account lockout policy changes are configuration changes, not logon failures, so they are not directly recorded as Event ID 4625. A policy change would typically trigger Event ID 4739 in the Security log (if policy change auditing is enabled) or be logged through Group Policy management. Event ID 4625 specifically represents an authentication failure, not an administrative modification to lockout thresholds. Since the evidence is a stream of failed logon events, a policy change would not be the correct conclusion.
- ✗
Successful account logon
Why it's wrong here
Successful account logons are logged with Event ID 4624, not Event ID 4625. Event ID 4625 explicitly indicates an authentication failure, and its Sub Status codes (e.g., 0xC000006D) confirm the reason the logon was denied. Successful logons would show a Logon Type, a unique Logon ID, and an elevated token, none of which appear in a failed logon event. Thus, interpreting 4625 as a success is a direct misreading of the event's semantic meaning.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CHFI
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security analyst reviews Windows Security Event Log and notices multiple Event ID 4625 entries for a single user account from various IP addresses within a short time frame. What is the MOST likely attack being attempted?
easy- ✓ A.Brute-force password attack
- B.Kerberos golden ticket attack
- C.ARP spoofing attack
- D.Pass-the-hash attack
Why A: Event ID 4625 indicates a failed logon attempt. Multiple such events for a single user account from various IP addresses within a short time frame is the classic signature of a brute-force password attack, where an attacker tries many passwords against one account from multiple source IPs to evade rate-limiting or IP-based blocking.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.