CompTIA
XK0-005 · Question #38
A system administrator has set up third-party log aggregation agents across several cloud instances. The systems administrator wants to create a dashboard of failed SSH attempts and the usernames…
The correct answer is A. /var/log/audit/audit.log. https://access.redhat.com/documentation/en- us/red_hat_enterprise_linux/6/html/security_guide/sec-understanding_audit_log_files
Security
Question
A system administrator has set up third-party log aggregation agents across several cloud instances. The systems administrator wants to create a dashboard of failed SSH attempts and the usernames used. Which of the following files should be watched by the agents?
Options
- A/var/log/audit/audit.log
- B/var/log/kern.log
- C/var/log/monitor
- D/etc/rsyslog.conf
How the community answered
(26 responses)- A92% (24)
- B4% (1)
- C4% (1)
Explanation
https://access.redhat.com/documentation/en- us/red_hat_enterprise_linux/6/html/security_guide/sec-understanding_audit_log_files
Topics
#Linux logging#auditd#SSH security#log aggregation
Community Discussion
No community discussion yet for this question.