200-201 Host-Based Analysis Practice Question
A junior analyst is asked to review a Linux server for evidence of unauthorized access. They want to see a chronological record of authentication-related messages, including successful and failed logins, generated by the system's authentication services. Which file should the analyst examine?
⚠ Common exam trap
The trap here is assuming all Linux distributions use the same authentication log path, when Red Hat-based systems instead write to /var/log/secure and some use journald.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/var/log/auth.log
Authentication-related messages on Debian and Ubuntu are written to /var/log/auth.log by services such as sshd, sudo, and PAM. Because this file captures both successful and failed login attempts in chronological order, it is the correct source for reviewing unauthorized access on the server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/var/log/dpkg.log
Why it's wrong here
/var/log/dpkg.log records package installation, upgrade, and removal actions performed by the Debian package manager. It can help identify recently installed software but contains no authentication events, so it cannot reveal successful or failed logins on the server.
- ✓
/var/log/auth.log
Why this is correct
On Debian and Ubuntu systems, /var/log/auth.log is the primary file where the authentication subsystem writes messages about successful and failed logins, sudo usage, and PAM events. Reviewing it gives the analyst the chronological authentication record they need to spot unauthorized access attempts on the server.
- ✗
/var/log/boot.log
Why it's wrong here
/var/log/boot.log contains messages generated during the system boot process, such as service startup output. It is useful for diagnosing boot failures but does not log user authentication activity, so it will not show the chronological login records the analyst needs.
- ✗
/var/log/kern.log
Why it's wrong here
/var/log/kern.log stores kernel-generated messages such as driver events, hardware errors, and firewall drops from iptables. While useful for troubleshooting and some security monitoring, it does not contain the authentication service records of logins and sudo usage that the analyst is looking for.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.