During a Linux forensic investigation, you find that the file /var/log/auth.log has been deleted. Which of the following artefacts would BEST help determine recent SSH login attempts?
The 'last' command parses the binary wtmp log (/var/log/wtmp) to display session records, including user, terminal, source IP, and login/logout timestamps. This directly captures successful local and SSH logins, making it the standard artifact for identifying recent successful authentication events. Concatenating the output with the 'last' command's default format provides a timeline of who accessed the system.
Why this answer
The 'last' command reads the /var/log/wtmp binary log file, which records all login and logout events, including SSH sessions. Even if /var/log/auth.log is deleted, the wtmp file persists and provides a reliable record of recent SSH login attempts, making option D the best choice.
Exam trap
The trap here is that candidates assume auth.log is the only source for SSH login data, overlooking the wtmp file that the 'last' command queries, which is a separate and more persistent artefact.
How to eliminate wrong answers
Option A is wrong because /etc/shadow stores hashed user passwords and password aging information, not login attempt records. Option B is wrong because /root/.bash_history logs only commands executed in a bash shell, not SSH authentication events. Option C is wrong because cron job entries in /etc/crontab schedule periodic tasks and do not record login attempts.