Courseiva
OS and Network Forensics →mediumMultiple Select

CHFI OS and Network Forensics Practice Question

Which TWO Windows Event IDs are associated with successful and failed logon events? (Select two.)

⚠ Common exam trap

It's easy for candidates to confuse Event ID 4648 (explicit credential usage) with a successful logon, but it only logs when credentials are explicitly supplied for a secondary logon, not the primary authentication event.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

4625

Event ID 4625 [CORRECT] is the Security log entry generated when a logon attempt fails, recording details such as the account name, logon type, and failure reason, so it directly answers the failed-logon half of the question. Event ID 4624 [CORRECT] is the Security log entry generated when a logon attempt succeeds, capturing the new logon's account, logon type, and authentication package, so it answers the successful-logon half. Together these two IDs are the canonical pair for tracking successful and failed interactive, network, and service logons. The other options do not belong: 4720 is logged when a user account is created, 7045 is a System log entry recording a new service being installed, and 4648 records a logon attempt using explicit credentials (such as RunAs), not a standard success or failure logon event.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    4720

    Why it's wrong here

    4720 is the Windows security event ID for user account creation, not for any kind of logon or authentication event. It fires when an administrator creates a new user account in Active Directory or a local SAM database. Since it does not represent an authentication attempt, it cannot be one of the event IDs associated with successful logon.

  • ✗

    7045

    Why it's wrong here

    7045 is the System log event ID for a new service being installed, recorded when a service is created or registered. This event belongs to the System log, not the Security log, and it tracks service installation activity rather than user authentication. It is unrelated to a logon attempt, whether successful or failed.

  • ✓

    4625

    Why this is correct

    4625 is the security event ID for a failed logon attempt, logged when a user presents incorrect credentials or the logon otherwise fails. This event is a core part of Windows authentication auditing, enabling analysts to spot brute-force attacks and lockout thresholds. It is correct for this question because it is one of the two primary logon event IDs, complementing 4624 for successful logon to cover the full authentication picture.

  • ✗

    4648

    Why it's wrong here

    4648 is the security event ID for an explicit credential logon, such as when a user invokes RunAs or maps a drive with alternate credentials. It indicates that a user explicitly supplied credentials for a process, but it does not itself confirm whether the authentication succeeded or failed; the resulting success or failure is audited separately as 4624 or 4625. Therefore it is not one of the event IDs associated directly with successful authentication.

  • ✓

    4624

    Why this is correct

    4624 is the security event ID that marks a successful logon, logged whenever a user authenticates effectively to a Windows system or domain. It includes rich metadata like logon type, user name, and source network address, making it essential for verifying access and tracing user activity. This is the definitive event for successful authentication, so it is a correct answer here.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.