GCFA Practice Question: Identification of Malicious and Normal Activity
When reviewing Windows Event Logs, which event ID indicates that a user has successfully performed an interactive login, and why is this critical for identifying unauthorized lateral movement?
⚠ Common exam trap
Candidates often confuse Event ID 4624 with 4625 (failed login). 4624 is for successful logins, which is the only way to confirm an attacker has actually accessed the system.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Event ID 4624, because it captures the logon type and source workstation.
Event ID 4624 is the primary indicator of a successful logon. Analyzing Logon Type 2 (interactive) or Logon Type 10 (Remote Desktop) allows analysts to track user access patterns. Monitoring these events helps distinguish between routine administrative access and abnormal logins occurring at odd hours or from unusual source IPs, which are standard red flags for compromised credentials being used by threat actors to traverse the network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Event ID 4688, because it tracks the exact time of user authentication.
Why it's wrong here
Event ID 4688 is used for process creation, not authentication. While it shows what programs are launched, it does not confirm the successful logon of a user. Relying on process creation logs for authentication audit trails is ineffective because they do not track the session establishment process.
- ✓
Event ID 4624, because it captures the logon type and source workstation.
Why this is correct
Event ID 4624 provides the critical context of how the user logged in, specifically via the Logon Type field. This allows investigators to differentiate between local interactive sessions and remote network sessions, which is essential for identifying unauthorized lateral movement across the domain during an incident investigation.
- ✗
Event ID 4720, because it logs user account creation activity.
Why it's wrong here
Event ID 4720 signifies that a user account was created. While this is a high-priority event, it is not an authentication event. Monitoring account creation is vital for detecting persistence, but it does not inform an investigator about the success or failure of a specific user login attempt.
- ✗
Event ID 4625, because it confirms the user has successfully bypassed MFA.
Why it's wrong here
Event ID 4625 indicates a failed logon attempt. It does not provide information regarding MFA bypass or successful authentication. Confusing failure events with success events will lead to incorrect conclusions during a forensic audit and may cause analysts to overlook active unauthorized sessions on the target system.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.