050-696 · Question #158
You suspect that someone has used BURGLAR.NLM to create a rogue admin user and has hidden it in your tree. Which file can you check to see if an unauthorized NLM was loaded?
The correct answer is B. SYS$LOG . ERR. On a Novell NetWare server, the SYS$LOG.ERR file is the primary system event log that records NLM loading activity, making it the correct file to inspect when investigating unauthorized NLMs such as BURGLAR.NLM.
Question
Options
- ASYSTEM.LOG
- BSYS$LOG . ERR
- CNLMLOAD . LOG
- DCONSOLE . $OG
- E$HISTORY.LOG
- FCONSOLELOG . TXT
- GUNAUTHORIZED . LOG
How the community answered
(42 responses)- B76% (32)
- C2% (1)
- D7% (3)
- F10% (4)
- G5% (2)
Why each option
On a Novell NetWare server, the SYS$LOG.ERR file is the primary system event log that records NLM loading activity, making it the correct file to inspect when investigating unauthorized NLMs such as BURGLAR.NLM.
SYSTEM.LOG is not a standard NetWare log file; NLM and system events are written to SYS$LOG.ERR, not a file by this name.
SYS$LOG.ERR is the standard system error and event log on Novell NetWare servers. It records NLM load and unload events, console messages, and system errors, so any attempt to load a rogue NLM like BURGLAR.NLM would leave a traceable entry in this file.
NLMLOAD.LOG is a fictitious filename; NetWare does not generate a dedicated NLM load log separate from SYS$LOG.ERR.
CONSOLE.$OG is not a valid NetWare file; it appears to be a misspelling and does not correspond to any real NetWare logging mechanism.
$HISTORY.LOG is not a recognized NetWare system log file for tracking NLM activity.
CONSOLELOG.TXT is not a standard NetWare log filename; the correct console and system log is SYS$LOG.ERR.
UNAUTHORIZED.LOG does not exist as a NetWare system file; NetWare has no built-in log by this name.
Concept tested: Novell NetWare NLM activity logging via SYS$LOG.ERR
Source: https://support.novell.com/techcenter/articles/ana19960201.html
Topics
Community Discussion
No community discussion yet for this question.