CHFI OS and Network Forensics Practice Question
Which Windows Event ID is generated when a new service is installed on the system?
⚠ Common exam trap
Many candidates confuse Event ID 7045 with Security log events like 4720 (user creation) or 4624 (logon), because they assume service installation is logged in the Security log, but it is actually recorded in the System log under a different event source.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
7045
Windows Event ID 7045 is specifically logged in the System event log when a new service is installed on the system. This event records the service name, image path, service type, and start mode, making it a critical artifact for forensic investigators tracking unauthorized service installations or persistence mechanisms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
4648
Why it's wrong here
Event ID 4648 is a Security log event that records an explicit credential logon, such as when a user runs a program with "Run as different user" or maps a network drive using alternate credentials. It captures the target account, source process, and logon type, but has no connection to service installation or the Service Control Manager. Therefore, it is incorrect for a new service event.
- ✗
4720
Why it's wrong here
Event ID 4720 is a Security log event under the Account Management category, generated when a new user account is created in Active Directory or the local SAM database. It includes the new account name, the subject who created it, and related security identifiers. This event is solely about account creation, not about the installation of a Windows service, so it does not match the required event.
- ✓
7045
Why this is correct
Event ID 7045 is the correct answer. It is a System log event emitted by the Service Control Manager whenever a new service is installed on the machine. The event details include the service name, executable path, service type (e.g., kernel driver or own process), start type, and the service account. This event is generated at the time of installation, making it the definitive indicator of a new service being added.
- ✗
4624
Why it's wrong here
Event ID 4624 is a Security log event that indicates a successful logon session, whether interactive, network, batch, or service. It contains the user account, logon type, source IP, and authentication package, but it is unrelated to the creation of a new service. Since this event tracks authentication success rather than service installation, it is not the correct event ID for a new service.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.