Event Logs Flashcards

1
Q

A user logged on to this computer

A

Event ID: 2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A user or computer logged on to this computer from the network

A

Event ID: 3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Batch logon type is used by batch servers, where processes may be executing on behalf of a user without their direct intervention

A

Event ID: 4

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A service was started by the service control manager

A

Event ID: 5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The workstation was unlocked

A

Event ID: 7

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A user logged on to the computer from the network. The user’s password was passed to the authentication package in its unhashed form

A

Event ID: 8

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A caller cloned its current token and specified new credentials for outbound connections

A

Event ID: 9

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A user logged on to this computer remotely using Terminal Services or Remote Desktop

A

Event ID: 10

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A user logged on to this computer with network credentials that were stored locally on the computer

A

Event ID: 11

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

A new process has been created

A

Event ID: 4688

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

The Windows Filtering Platform has allowed connection

A

Event ID: 5156

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A service was installed in the system

A

Event ID: 7045

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

A registry value was modified

A

Event ID: 4657

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

an object was deleted

A

Event ID: 4660

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

an attempt was made to access an object

A

Event ID: 4663

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Service has entered the stopped state.

A

Event ID: 7036

17
Q

The start type of service was changed from autostart to demand start/auto start to disabled

A

Event ID: 7040