CHFI OS and Network Forensics Practice Question
Which TWO Windows Event IDs are associated with successful logon or explicit credential usage? (Choose TWO.)
⚠ Common exam trap
Many exam-takers confuse Event ID 4625 (failed logon) with 4624 (successful logon), or mistakenly associate 4720 (account creation) with logon activity, while overlooking the specific purpose of 4648 for explicit credential usage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
4648
Event ID 4624 [CORRECT] is logged in the Windows Security log when a logon attempt succeeds, recording details such as logon type, account name, and authentication package, so it directly matches the 'successful logon' part of the question. Event ID 4648 [CORRECT] is generated when a process attempts an explicit logon using credentials other than those of the current logged-on user (for example, RunAs or passing alternate credentials), which matches the 'explicit credential usage' part. By contrast, 4720 is logged when a new user account is created, 4625 records a failed logon attempt, and 7045 is a System log event indicating a new service was installed — none of these represent a successful logon or explicit credential use.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
4648
Why this is correct
Event ID 4648 records a logon attempt using explicit credentials, such as when a user runs a process with `runas` or supplies alternate domain credentials for a network connection. This satisfies the stem’s constraint of “explicit credential usage” because the event logs the target account and the source process, distinguishing it from interactive logon events like 4624.
- ✗
4720
Why it's wrong here
Event ID 4720 records creation of a user account, an account-management event unrelated to logon or explicit credential usage. It is tempting because it is a common audited Security event, and would be correct where the question asks about user account creation or identity provisioning activity.
- ✓
4624
Why this is correct
Event ID 4624 is logged in the Windows Security log whenever a logon succeeds, recording the account, logon type and source. It is the canonical success counterpart to 4625, directly satisfying the question's requirement for a successful logon event.
- ✗
4625
Why it's wrong here
Event ID 4625 records a failed logon attempt, so it evidences unsuccessful authentication rather than successful logon or explicit credential use. It is tempting because it is a core Security logon event, and would be correct where the question asks about failed logons or brute-force detection.
- ✗
7045
Why it's wrong here
Event ID 7045 records a new service being installed, which is service-installation telemetry and not a logon event. It is tempting because it appears in security monitoring for persistence, and would be the right answer where the question asks about service creation or suspicious driver installation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.