During lateral movement, a server logs Event ID 7045 seconds after a remote SMB session. The analyst must identify the Windows event source that confirms the service was installed on that endpoint. Which event source should be selected?
Select an answer to reveal the explanation.
Short Explanation
Think of Event ID 7045 like a sign-in log for a new Windows service: it tells you something was installed, but not the full story. You want the Service Control Manager source because that is what records service installation events, while other sources only point to nearby clues. Don't chase Security-Auditing just because it looks official; match the event ID to its actual source.
Full Explanation
Event ID 7045 is generated by the Windows Service Control Manager when a service is installed, making it a high-value indicator of persistence or lateral movement when paired with remote logon, SMB, or PsExec-like service names. The correct source is Service Control Manager because it owns the System-log service installation record, including service name, binary path, start type, and account used. The Microsoft-Windows-Security-Auditing source is wrong because service installation can also appear as Security event 4697, but that is a separate auditing record, not the source of 7045. The Microsoft-Windows-Kernel-Power source is wrong because it reports power-state transitions, not service creation. The Microsoft-Windows-TaskScheduler source is wrong because it records scheduled task creation and modification, which is a different persistence mechanism. Exam caveat: CompTIA expects you to match event IDs to their native sources and log names before assuming a correlation is proof of compromise. Operational check: search the SIEM for Event ID 7045 on the target host, then pivot to the service binary path, parent process, and any Event ID 4624 logon or 5145 share-access records from the same time window.