nerdexam
Novell

050-696 · Question #158

You suspect that someone has used BURGLAR.NLM to create a rogue admin user and has hidden it in your tree. Which file can you check to see if an unauthorized NLM was loaded?

The correct answer is B. SYS$LOG . ERR. On a Novell NetWare server, the SYS$LOG.ERR file is the primary system event log that records NLM loading activity, making it the correct file to inspect when investigating unauthorized NLMs such as BURGLAR.NLM.

Server Management and Maintenance

Question

You suspect that someone has used BURGLAR.NLM to create a rogue admin user and has hidden it in your tree. Which file can you check to see if an unauthorized NLM was loaded?

Options

  • ASYSTEM.LOG
  • BSYS$LOG . ERR
  • CNLMLOAD . LOG
  • DCONSOLE . $OG
  • E$HISTORY.LOG
  • FCONSOLELOG . TXT
  • GUNAUTHORIZED . LOG

How the community answered

(42 responses)
  • B
    76% (32)
  • C
    2% (1)
  • D
    7% (3)
  • F
    10% (4)
  • G
    5% (2)

Why each option

On a Novell NetWare server, the SYS$LOG.ERR file is the primary system event log that records NLM loading activity, making it the correct file to inspect when investigating unauthorized NLMs such as BURGLAR.NLM.

ASYSTEM.LOG

SYSTEM.LOG is not a standard NetWare log file; NLM and system events are written to SYS$LOG.ERR, not a file by this name.

BSYS$LOG . ERRCorrect

SYS$LOG.ERR is the standard system error and event log on Novell NetWare servers. It records NLM load and unload events, console messages, and system errors, so any attempt to load a rogue NLM like BURGLAR.NLM would leave a traceable entry in this file.

CNLMLOAD . LOG

NLMLOAD.LOG is a fictitious filename; NetWare does not generate a dedicated NLM load log separate from SYS$LOG.ERR.

DCONSOLE . $OG

CONSOLE.$OG is not a valid NetWare file; it appears to be a misspelling and does not correspond to any real NetWare logging mechanism.

E$HISTORY.LOG

$HISTORY.LOG is not a recognized NetWare system log file for tracking NLM activity.

FCONSOLELOG . TXT

CONSOLELOG.TXT is not a standard NetWare log filename; the correct console and system log is SYS$LOG.ERR.

GUNAUTHORIZED . LOG

UNAUTHORIZED.LOG does not exist as a NetWare system file; NetWare has no built-in log by this name.

Concept tested: Novell NetWare NLM activity logging via SYS$LOG.ERR

Source: https://support.novell.com/techcenter/articles/ana19960201.html

Topics

#SYS$LOG.ERR#unauthorized NLM#BURGLAR.NLM#server security log

Community Discussion

No community discussion yet for this question.

Full 050-696 Practice