CHFI OS and Network Forensics • Set 2
CHFI OS and Network Forensics Practice Test 2 — 15 questions with explanations. Free, no signup.
During a forensic investigation of a compromised Linux server, you find the following entry in /var/log/auth.log: 'Mar 10 03:14:15 server sshd[1234]: Accepted publickey for root from 10.0.0.5 port 54321 ssh2: RSA SHA256:AbCdEf123456'. Which artifact should you examine next to determine if unauthorized key-based access occurred?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.