Courseiva
OS and Network Forensics →mediumMultiple Select

CHFI OS and Network Forensics Practice Question

Which TWO Windows Event IDs are associated with successful logon or explicit credential usage? (Choose TWO.)

⚠ Common exam trap

Many exam-takers confuse Event ID 4625 (failed logon) with 4624 (successful logon), or mistakenly associate 4720 (account creation) with logon activity, while overlooking the specific purpose of 4648 for explicit credential usage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

4648

Event ID 4624 [CORRECT] is logged in the Windows Security log when a logon attempt succeeds, recording details such as logon type, account name, and authentication package, so it directly matches the 'successful logon' part of the question. Event ID 4648 [CORRECT] is generated when a process attempts an explicit logon using credentials other than those of the current logged-on user (for example, RunAs or passing alternate credentials), which matches the 'explicit credential usage' part. By contrast, 4720 is logged when a new user account is created, 4625 records a failed logon attempt, and 7045 is a System log event indicating a new service was installed — none of these represent a successful logon or explicit credential use.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    4648

    Why this is correct

    Event ID 4648 records a logon attempt using explicit credentials, such as when a user runs a process with `runas` or supplies alternate domain credentials for a network connection. This satisfies the stem’s constraint of “explicit credential usage” because the event logs the target account and the source process, distinguishing it from interactive logon events like 4624.

  • ✗

    4720

    Why it's wrong here

    Event ID 4720 records creation of a user account, an account-management event unrelated to logon or explicit credential usage. It is tempting because it is a common audited Security event, and would be correct where the question asks about user account creation or identity provisioning activity.

  • ✓

    4624

    Why this is correct

    Event ID 4624 is logged in the Windows Security log whenever a logon succeeds, recording the account, logon type and source. It is the canonical success counterpart to 4625, directly satisfying the question's requirement for a successful logon event.

  • ✗

    4625

    Why it's wrong here

    Event ID 4625 records a failed logon attempt, so it evidences unsuccessful authentication rather than successful logon or explicit credential use. It is tempting because it is a core Security logon event, and would be correct where the question asks about failed logons or brute-force detection.

  • ✗

    7045

    Why it's wrong here

    Event ID 7045 records a new service being installed, which is service-installation telemetry and not a logon event. It is tempting because it appears in security monitoring for persistence, and would be the right answer where the question asks about service creation or suspicious driver installation.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.