Courseiva

GSEC Windows Security Infrastructure Practice Question

A security analyst is investigating a suspected credential theft attack on a Windows 10 workstation. The analyst reviews the Security event log and sees Event ID 4648 (A logon was attempted using explicit credentials) occurring repeatedly for a service account. Which of the following best describes the significance of this event in the context of credential theft?

⚠ Common exam trap

The trap here is assuming that any security event involving a service account indicates credential theft, without verifying the specific event ID and its meaning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It indicates that the service account's credentials were used to run a process with explicit credentials, which could be a sign of pass-the-hash or credential reuse.

Event ID 4648 is generated when a logon is attempted using explicit credentials, such as with RunAs or a scheduled task. In credential theft, attackers may use stolen credentials to start processes, causing this event. Repeated occurrences for a service account can signal malicious activity. Other events like 4625, 4740, or 4672 have different meanings and are not directly indicative of explicit credential use.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It indicates that the service account was granted special privileges, such as SeDebugPrivilege, which is a common post-exploitation step.

    Why it's wrong here

    Privilege assignment events are logged with Event IDs 4672 (special privileges assigned) or 4673 (privileged service called). Event 4648 does not relate to privilege assignment. While privilege escalation is a concern, this event does not indicate that; it indicates explicit credential use.

  • ✗

    It indicates that the service account's password was changed, which is a common persistence technique after credential theft.

    Why it's wrong here

    Password changes are logged with Event ID 4723 or 4724, not 4648. Event 4648 specifically relates to logon attempts with explicit credentials. Therefore, this option misidentifies the event and its meaning in the context of credential theft.

  • ✗

    It indicates that the service account was locked out due to multiple failed logon attempts, which is a sign of brute-force attack.

    Why it's wrong here

    Account lockouts are recorded with Event ID 4740. Event 4648 does not indicate lockout; it indicates a successful or attempted logon using explicit credentials. Brute-force attacks typically generate Event ID 4625 (failed logon). Thus, this option is incorrect for the given event.

  • ✓

    It indicates that the service account's credentials were used to run a process with explicit credentials, which could be a sign of pass-the-hash or credential reuse.

    Why this is correct

    Event ID 4648 is logged when a process attempts to log on using explicitly provided credentials, such as when using RunAs or a scheduled task. In a credential theft scenario, an attacker might use stolen credentials to start a process, generating this event. Repeated occurrences for a service account can indicate malicious use of those credentials.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.