This event gets logged twice (duplicate) by the domain
controller. Unlike event 610, an event 620 does not accompany
this event.
The DC logs this event for both trusted and trusting domains.
There is no way to make a distinction.
If directory service access auditing is turned on, the DC
also logs an event 565 (object opened) and 564 (object deleted)
where the object service is LSA and the object type is TrustedDomainObject.
Object name identifies the domain.
See also event IDs 610, 611 and 620