CHFI OS and Network Forensics Practice Question
Which Windows Event ID is generated when a new service is installed on a system?
⚠ Common exam trap
Test-takers frequently confuse Event ID 7045 with Event ID 4697 (service installation in the Security log) or mistakenly associate Event ID 4624 (logon success) with service accounts, but the EC-CHFI exam specifically tests the System log Event ID 7045 for service installation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
7045
Event ID 7045 is logged in the Windows System event log when a new service is installed on the system. This event is generated by the Service Control Manager (SCM) and records details such as the service name, binary path, service type, and start mode, making it a critical artifact for forensic analysis of unauthorized service installations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
4624
Why it's wrong here
Event ID 4624 is an authentication audit event generated in the Windows Security log whenever a user successfully logs on to the computer. It records details such as the logon type (interactive, network, batch, etc.), user account, source workstation, and logon process. A newly installed service does not generate a user logon event; service creation is logged separately by the Service Control Manager, so 4624 cannot be the correct event for a new service installation.
- ✓
7045
Why this is correct
Event ID 7045 is the Windows System log event emitted by the Service Control Manager whenever a new service is installed or registered on the system. It contains the service name, image path, service type, start type, and the account under which the service runs. This is the definitive event for detecting service installations, although on modern Windows versions event 4697 provides similar service-creation auditing in the Security log.
- ✗
4648
Why it's wrong here
Event ID 4648 is an audit event that records a logon attempt using explicit credentials, such as when a user invokes the RunAs command or maps a drive with alternate account credentials. It appears in the Security log with the target server name, user name, and process that requested the alternate credentials. The installation of a service is performed by the Service Control Manager in system context via service APIs, not through an explicit credential logon, so 4648 is incorrect here.
- ✗
4720
Why it's wrong here
Event ID 4720 is a Security log audit event generated when a new user account is created in the local Security Accounts Manager (SAM) or in Active Directory. It identifies the account created, the account name of the user who performed the creation, and the workstation or domain controller involved. Service installation does not create a user account; the Service Control Manager registers the service binary path and service configuration, which is captured by event 7045, not by an account-management event like 4720.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.