Courseiva
OS and Network Forensics →mediumMultiple Select

CHFI OS and Network Forensics Practice Question

Which THREE of the following are Windows Event IDs that are particularly useful for investigating account logon activities?

⚠ Common exam trap

EC-Council often tests the distinction between logon-specific events (4624, 4625, 4648) and other security events like object access (4656) or system changes (7045), so candidates must remember that only events in the 462x series directly track account logon attempts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

4625 - An account failed to log on

Option A (4625 - An account failed to log on) is correct because it records failed authentication attempts in the Security log, which is essential for detecting brute-force, password-spraying, or unauthorized access attempts. Option B (4648 - A logon was attempted using explicit credentials) is correct because it captures scenarios where a process or user supplies alternate credentials (e.g., RunAs, scheduled tasks, or lateral movement with explicit creds), which is critical for tracing credential misuse. Option C (4624 - An account was successfully logged on) is correct because it documents successful logons, including logon type (2 interactive, 3 network, 10 RDP, etc.), enabling investigators to establish a timeline of legitimate or suspicious access. Option D (4656 - A handle to an object was requested) is not a logon event; it relates to object access auditing and handle requests, so it does not directly evidence account logon activity. Option E (7045 - A service was installed in the system) is a System log event about service installation (persistence), not an account logon event, so it is not relevant to investigating logon activities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    4625 - An account failed to log on

    Why this is correct

    Event ID 4625 is generated on the domain controller or local machine whenever a logon attempt fails, regardless of whether the failure was due to a bad password, a nonexistent account, or a locked-out account. The event contains critical forensic details such as the account name, the source network address, logon type, and the specific sub-status code (e.g., 0xC000006A for bad password). Analysts rely on 4625 spikes to detect password spraying or brute-force attacks, and correlating this ID with successful logons (4624) for the same account shortly afterward can reveal successful credential compromise after repeated failures.

  • ✓

    4648 - A logon was attempted using explicit credentials

    Why this is correct

    Event ID 4648 fires when a user attempts to log on using explicit credentials, meaning they supplied alternate account credentials (e.g., via "Run as different user" or a scheduled task with stored credentials) rather than using their already-established session. This is an advanced threat behavior because attackers often use explicit credentials to move laterally or elevate privileges without triggering a full interactive logon. The event records both the target account and the account that initiated the request, plus the process that requested the logon, making it invaluable for detecting pass-the-hash-like or credential-theft scenarios where legitimate tools invoke secondary credentials.

  • ✓

    4624 - An account was successfully logged on

    Why this is correct

    Event ID 4624 records every successful logon to the system and is the foundational audit event for establishing a baseline of normal authentication activity. Crucially, the event's Logon Type field distinguishes among interactive (2), network (3), batch (4), service (5), and other methods, which helps investigators spot anomalous logon behavior — for example, a service account appearing with Logon Type 2 from an unexpected workstation. While a single 4624 is not inherently malicious, an unusual pairing of 4624 with a preceding 4625 failure, or a 4624 occurring outside normal business hours, often signals a credential attack or compromised account.

  • ✗

    4656 - A handle to an object was requested

    Why it's wrong here

    Event ID 4656 is logged when a process requests a handle to an object (file, registry key, process, etc.) and is part of Object Access auditing, not logon auditing. To generate this event, the system must have both the object's SACL auditing flag enabled and the "Audit Object Access" policy configured; otherwise, it is a candidate for malicious attempts to evade access logging in the context of Windows event logon analysis.

  • ✗

    7045 - A service was installed in the system

    Why it's wrong here

    Event ID 7045 is emitted by the Service Control Manager when a new service is installed on the system, and it is not related to user logon events at all. This ID is closely monitored by security teams because attackers frequently install persistence mechanisms — like backdoor services or kernel drivers — using tools such as `sc create` or Metasploit's `persistence` module. In the context of a logon-related question, 7045 is a distractor: it indicates a change in system state, not an authentication attempt, and should be analyzed with service installation timelines rather than logon failure or success patterns.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.