Courseiva
OS and Network Forensics →easyMultiple Choice

CHFI OS and Network Forensics Practice Question

Which Windows Event ID is generated when a service is installed on a system?

⚠ Common exam trap

Candidates often confuse Event ID 7045 with process creation (4688) or logon events (4624), because service installation involves starting a process and may require authentication, but the specific event for the installation itself is uniquely 7045.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

7045

Event ID 7045 is logged in the Windows System event log when a new service is installed on the system. This event records the service name, image path, service type, and start mode, making it a critical artifact for forensic investigators tracking unauthorized service installations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    4624

    Why it's wrong here

    Event ID 4624 is a Windows Security log event that records successful logon sessions, generated by LSASS when a user authenticates and is issued an access token. It captures details such as logon type, source IP, and the logged-on account, but it has no direct relationship to the Service Control Manager's service registration workflow. While an attacker installing a service may first log on interactively, that logon would be an incidental precursor, not the event generated by the installation itself.

  • ✓

    7045

    Why this is correct

    Event ID 7045 is a System log event generated by the Service Control Manager (SCM) when a new service is installed or registered on a Windows host. It records the service name, executable path, service type, and start type, and is the definitive artifact that identifies service installation, even if the service binary is later removed. This event appears in the System log and can be correlated with Process Creation event 4688 to trace which process launched the installation command.

  • ✗

    4688

    Why it's wrong here

    Event ID 4688 is a Security audit event for process creation, logged when any process is spawned on the system; it includes the new process ID, command line, parent process ID, and the user context if command-line auditing is enabled. Installing a service often launches an installer or command-line utility such as sc.exe, which would generate a 4688 for that executable, but 4688 only describes the execution of a process, not the SCM's subsequent service registration. The sole event explicitly tied to the completion of a service installation remains 7045.

  • ✗

    4720

    Why it's wrong here

    Event ID 4720 is a Security audit event generated when a new user account is created in Active Directory or the local Security Account Manager, capturing the subject who created the account and the new account's security identifier. Service installation may optionally trigger creation of a dedicated service account, which would produce a 4720, but that event only reflects user account provisioning, not the installation or configuration of the service itself. Therefore, 4720 is unrelated as the direct answer for a service-installed event.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.