Courseiva
OS and Network Forensics →easyMultiple Choice

CHFI OS and Network Forensics Practice Question

Which Windows Event ID is generated when a new service is installed on a system?

⚠ Common exam trap

Test-takers frequently confuse Event ID 7045 with Event ID 4697 (service installation in the Security log) or mistakenly associate Event ID 4624 (logon success) with service accounts, but the EC-CHFI exam specifically tests the System log Event ID 7045 for service installation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

7045

Event ID 7045 is logged in the Windows System event log when a new service is installed on the system. This event is generated by the Service Control Manager (SCM) and records details such as the service name, binary path, service type, and start mode, making it a critical artifact for forensic analysis of unauthorized service installations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    4624

    Why it's wrong here

    Event ID 4624 is an authentication audit event generated in the Windows Security log whenever a user successfully logs on to the computer. It records details such as the logon type (interactive, network, batch, etc.), user account, source workstation, and logon process. A newly installed service does not generate a user logon event; service creation is logged separately by the Service Control Manager, so 4624 cannot be the correct event for a new service installation.

  • ✓

    7045

    Why this is correct

    Event ID 7045 is the Windows System log event emitted by the Service Control Manager whenever a new service is installed or registered on the system. It contains the service name, image path, service type, start type, and the account under which the service runs. This is the definitive event for detecting service installations, although on modern Windows versions event 4697 provides similar service-creation auditing in the Security log.

  • ✗

    4648

    Why it's wrong here

    Event ID 4648 is an audit event that records a logon attempt using explicit credentials, such as when a user invokes the RunAs command or maps a drive with alternate account credentials. It appears in the Security log with the target server name, user name, and process that requested the alternate credentials. The installation of a service is performed by the Service Control Manager in system context via service APIs, not through an explicit credential logon, so 4648 is incorrect here.

  • ✗

    4720

    Why it's wrong here

    Event ID 4720 is a Security log audit event generated when a new user account is created in the local Security Accounts Manager (SAM) or in Active Directory. It identifies the account created, the account name of the user who performed the creation, and the workstation or domain controller involved. Service installation does not create a user account; the Service Control Manager registers the service binary path and service configuration, which is captured by event 7045, not by an account-management event like 4720.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.