nerdexam
Oracle

1Z0-822 · Question #132

Examine the following information: Which statement describes the user auuser audit mask?

The correct answer is A. All failed and successful lo events, all failed and successful am events will be logged, no ss. The Trusted Solaris environment provides audit classes including: ss - Change system state no - Invalid class lo - Login or logout Lists the audit classes that are audited for this user. Modifications to the system-wide classes are prefixed by a caret (^). Classes that are…

Advanced User Management

Question

Examine the following information:

Which statement describes the user auuser audit mask?

Exhibit

1Z0-822 question #132 exhibit

Options

  • AAll failed and successful lo events, all failed and successful am events will be logged, no ss
  • BAll failed and successful lo events, all failed and successful am events and successful ss events
  • CAll failed and successful lo events, all failed and successful am events and failed ss events will be
  • DAll failed and successful lo events and all failed and successful ss events will be logged.

How the community answered

(51 responses)
  • A
    55% (28)
  • B
    6% (3)
  • C
    27% (14)
  • D
    12% (6)

Explanation

  • The Trusted Solaris environment provides audit classes including: ss - Change system state no - Invalid class lo - Login or logout Lists the audit classes that are audited for this user. Modifications to the system-wide classes are prefixed by a caret (^). Classes that are added to the system-wide classes are not prefixed by a Lists the audit classes that are never audited for the user, even if these audit events are audited system-wide. Modifications to the system-wide classes are prefixed by a caret (^). * Process preselection mask ?A combination of the system-wide audit mask and the user- specific audit mask, if a user audit mask has been specified. When a user logs in, the login process combines the preselected classes to establish the process preselection mask for the user's processes. The process preselection mask specifies whether events in each audit class are to generate audit records. The following algorithm describes how the system obtains the user's process preselection mask: (system-wide default flags + always-audit-classes) - never-audit-classes * getent user_attr - get entries from administrative database getent gets a list of entries from the administrative database specified by database. The information generally comes from one or more of the sources that are specified for the database in /etc/nsswitch.conf.

Topics

#audit mask#user auditing#auditconfig#audit events

Community Discussion

No community discussion yet for this question.

Full 1Z0-822 Practice