GCIH Incident Response and Cyber Investigation Practice Question
A GCIH incident responder is conducting a forensic investigation of a compromised Windows system. The responder needs to determine which user accounts were used to log on to the system and whether any unauthorized access occurred. Which Windows event log should the responder examine to find successful and failed logon attempts?
⚠ Common exam trap
The trap here is assuming that the System log contains logon events because it sounds like it would, but authentication is exclusively in the Security log.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security log
The Security log is the authoritative source for authentication events on Windows. It records successful logons (event ID 4624) and failed logons (event ID 4625), along with details such as the user account, logon type, and source workstation. By analyzing this log, the responder can determine which accounts were used and identify any unauthorized access attempts, fulfilling the investigation requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application log
Why it's wrong here
The Application log records events generated by applications, such as errors or warnings from software. It does not contain security-related events like logon attempts. While it may provide clues about application crashes or errors, it is not the correct source for auditing user logon activity. The responder should look elsewhere for authentication events.
- ✗
Setup log
Why it's wrong here
The Setup log records events related to application and Windows setup, such as installation or update activities. It does not contain logon events or authentication data. It is used primarily for troubleshooting installation issues. Therefore, it is not the appropriate log for investigating user logons on a compromised system.
- ✓
Security log
Why this is correct
The Security log records security-related events, including successful and failed logon attempts (event IDs 4624 and 4625), account management, and privilege use. This is the primary log for auditing authentication activity. By examining it, the responder can identify which accounts were used and whether unauthorized access occurred, directly addressing the investigation goal.
- ✗
System log
Why it's wrong here
The System log contains events logged by Windows system components, such as service start failures or hardware errors. It does not record user logon events. While it can be useful for troubleshooting system issues, it is not relevant for tracking authentication attempts. The responder should not rely on this log for logon information.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.