ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 85 - 212-82 discussion

Report
Export

Gideon, a forensic officer, was examining a victim's Linux system suspected to be involved in online criminal activities. Gideon navigated to a directory containing a log file that recorded information related to user login/logout. This information helped Gideon to determine the current login state of cyber criminals in the victim system, identify the Linux log file accessed by Gideon in this scenario.

A.
/va r/l og /mysq Id. log
Answers
A.
/va r/l og /mysq Id. log
B.
/va r/l og /wt m p
Answers
B.
/va r/l og /wt m p
C.
/ar/log/boot.iog
Answers
C.
/ar/log/boot.iog
D.
/var/log/httpd/
Answers
D.
/var/log/httpd/
Suggested answer: B

Explanation:

/var/log/wtmp is the Linux log file accessed by Gideon in this scenario. /var/log/wtmp is a log file that records information related to user login/logout, such as username, terminal, IP address, and login time. /var/log/wtmp can be used to determine the current login state of users in a Linux system. /var/log/wtmp can be viewed using commands such as last, lastb, or utmpdump1.

Reference: Linux Log Files

asked 18/09/2024
Salih Igde
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first