GCIH Network and Log Investigations Practice Question
An analyst is investigating a suspected Pass-the-Hash attack within an Active Directory environment. Which TWO Windows Security Event Log IDs should the analyst examine to detect the use of stolen NTLM credential material for lateral movement? (Choose TWO)
⚠ Common exam trap
Candidates frequently select Event ID 4625, confusing failed logon attempts with the successful authentication events characteristic of valid stolen hash utilization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Event ID 4624 (An account was successfully logged on)
Event ID 4624 records successful logons, and specifying Logon Type 3 (Network) combined with NTLM authentication indicates a potential Pass-the-Hash event when originating from an unusual source. Event ID 4672 details special privileges assigned to new logins, helping verify if the compromised security context obtained administrative privileges across the domain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Event ID 4624 (An account was successfully logged on)
Why this is correct
Event ID 4624 is critical because Pass-the-Hash attacks result in successful authentication sessions without requiring plaintext passwords. Analysts examine the logon type and authentication package fields within this event to identify anomalous network logons utilizing NTLM.
- ✗
Event ID 4625 (An account failed to log on)
Why it's wrong here
Event ID 4625 logs failed authentication attempts, which occur when credentials are mistyped or accounts are locked out. Since Pass-the-Hash attacks reuse valid cryptographic hashes harvested from memory, they successfully authenticate and rarely generate standard failure logs.
- ✓
Event ID 4672 (Special privileges assigned to new logon)
Why this is correct
Event ID 4672 is generated alongside successful administrative logons when high-privilege accounts are utilized. Identifying this event immediately following a network logon helps analysts determine if the threat actor successfully leveraged harvested administrative hash material.
- ✗
Event ID 4720 (A user account was created)
Why it's wrong here
Event ID 4720 records the creation of local or domain user accounts during persistence or privilege escalation phases. It is unrelated to the authentication mechanism used when an attacker utilizes a stolen NTLM hash to authenticate over the network.
- ✗
Event ID 1102 (The audit log was cleared)
Why it's wrong here
Event ID 1102 indicates that the Windows Security Event Log was manually cleared by an administrator or an attacker covering their tracks. While useful for detecting anti-forensic activities, it does not provide evidence of authentication mechanisms or Pass-the-Hash execution.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.