200-201 Host-Based Analysis Practice Question
A security analyst is examining a Linux host and wants to identify which user account was used to execute a specific command that modified a critical system file. Which of the following files would provide the MOST direct evidence of the user who executed the command?
⚠ Common exam trap
The trap here is assuming that bash_history or auth.log will show the command and user, but bash_history is per-user and modifiable, while auth.log only shows authentication events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/var/log/audit/audit.log
The audit log, managed by auditd, is designed to capture security-relevant events, including command execution with user context. It logs the UID and EUID, so an analyst can determine exactly which user account executed the command that modified the critical file. Other logs may not capture this level of detail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/var/log/auth.log
Why it's wrong here
This file records authentication events, such as logins and sudo usage, but it does not log every command executed by users. It may show that a user logged in or used sudo, but it does not provide a direct record of the specific command that modified the file. Therefore, it is not the most direct evidence.
- ✗
/var/log/syslog
Why it's wrong here
The syslog file contains system messages, including some command-related events, but it does not reliably log every command executed by users. It is more focused on system services and kernel messages, so it would not provide direct evidence of the user who executed a specific command.
- ✓
/var/log/audit/audit.log
Why this is correct
The audit log, when auditd is configured, records detailed system call and command execution events, including the user ID (UID) and effective user ID (EUID) of the process that executed the command. This provides direct evidence of which user account was used to run the command, making it the most reliable source for this scenario.
- ✗
/home/<user>/.bash_history
Why it's wrong here
The bash history file for a specific user records commands they typed in interactive shells, but it is not a system-wide log and can be easily modified or deleted by the user. It also does not include timestamps by default, making it unreliable for correlating with the file modification time.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.