XK0-006 Security Practice Question
A security analyst is investigating a potential breach and needs to examine user login history. Which THREE commands or log files provide information about user logins? (Select THREE.)
⚠ Common exam trap
Watch out — candidates often confuse general system logs like /var/log/syslog or /var/log/messages with dedicated authentication logs, but these files lack the structured login/out records that commands like last, lastlog, and lastb specifically parse.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
last
The `last` command (A) reads /var/log/wtmp and displays a chronological list of all successful user logins, logouts, and system reboots, making it a primary tool for reviewing login history. The `lastlog` command (B) reads /var/log/lastlog and reports the most recent login for every user account, which is useful for spotting accounts that have never logged in or that logged in unexpectedly. The `lastb` command (C) reads /var/log/btmp and lists failed login attempts, which is essential when investigating a potential breach involving brute-force or unauthorized access attempts. Options D and E are incorrect because /var/log/syslog and /var/log/messages are general-purpose system logs that capture a broad mix of kernel, service, and application messages; while they may incidentally contain authentication-related entries, they are not dedicated login-history sources like wtmp, lastlog, and btmp.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
last
Why this is correct
The `last` command reads `/var/log/wtmp`, listing successful login sessions with usernames, terminal lines, source hosts and timestamps. This directly satisfies the analyst's need to examine user login history during breach investigation, showing who logged in, from where, and when.
- ✓
lastlog
Why this is correct
The `lastlog` command reads `/var/log/lastlog` and reports each user's most recent login time, displaying the timestamp and originating terminal or host. This directly satisfies the analyst's need to examine user login history, since it exposes the latest successful authentication per account, helping identify compromised credentials or unexpected access.
- ✓
lastb
Why this is correct
`lastb` reads `/var/log/btmp`, recording failed login attempts with source host, timestamp and username. Since the analyst investigates a potential breach, failed authentications often reveal brute-force or credential-stuffing activity, so this log directly satisfies the requirement to examine login history alongside successful-login sources.
- ✗
/var/log/syslog
Why it's wrong here
/var/log/syslog captures general system events and may incidentally note authentication activity, but it is not the dedicated record of user logins. It tempts because it is the primary Debian/Ubuntu syslog file, yet login history is held in wtmp, btmp and the journal, which the question targets.
- ✗
/var/log/messages
Why it's wrong here
/var/log/messages records general system and service messages, including some authentication notices, but on systemd distributions login records live in wtmp/btmp and the journal. It tempts because it is a central syslog file that often mentions logins, yet it is not the authoritative source for user login history.
Go deeper
Related to this question
Learn chapter
Firewall and Security Basics
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
Key term
Syslog
Syslog is a standard protocol used to send and store log messages from network devices and servers to a central logging server for monitoring and troubleshooting.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.