nerdexam
Oracle

1Z0-822 · Question #17

You are the primary administrator for a set of Oracle Solaris 11 servers. You noticed some changes to configuration files. You are concerned that someone may have unauthorized access and that an…

The correct answer is A. Solaris auditing. Solaris auditing keeps a record of how the system is being used. The audit service includes tools to assist with the analysis of the auditing data. not C: Basic Audit Reporting Tool BART is a file tracking tool that operates entirely at the file system level. Using BART gives…

Advanced User Management

Question

You are the primary administrator for a set of Oracle Solaris 11 servers. You noticed some changes to configuration files. You are concerned that someone may have unauthorized access and that an authorized user may be abusing the access privilege. You want to track users of these systems to determine what tasks each user performs. Select the best way to gather this information.

Options

  • ASolaris auditing
  • Bthe system/event service
  • Cthe system-logging service
  • DBasic Audit Reporting Tool
  • ESystem Extended Accounting

How the community answered

(35 responses)
  • A
    83% (29)
  • B
    9% (3)
  • C
    3% (1)
  • D
    6% (2)

Explanation

Solaris auditing keeps a record of how the system is being used. The audit service includes tools to assist with the analysis of the auditing data. not C: Basic Audit Reporting Tool BART is a file tracking tool that operates entirely at the file system level. Using BART gives you the ability to quickly, easily, and reliably gather information about the components of the software stack that is installed on deployed systems. Using BART can greatly reduce the costs of administering a network of systems by simplifying time-consuming administrative tasks. * The audit service makes the following possible: Monitoring security-relevant events that take place on the host Recording the events in a network-wide audit trail Detecting misuse or unauthorized activity Reviewing patterns of access and the access histories of individuals and objects Discovering attempts to bypass the protection mechanisms Discovering extended use of privilege that occurs when a user changes identity * Auditing is the collecting of data about the use of system resources. The audit data provides a record of security-related system events. This data can then be used to assign responsibility for actions that take place on a host. Successful auditing starts with two security features: identification and authentication. At each login, after a user supplies a user name and password, a unique audit session ID is generated and associated with the user's process. The audit session ID is inherited by every process that is started during the login session. Even if a user changes identity within a single session, all user actions are tracked with the same audit session ID.

Topics

#Solaris auditing#user activity tracking#audit service#security monitoring

Community Discussion

No community discussion yet for this question.

Full 1Z0-822 Practice