Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

During a forensic analysis of a compromised Linux server, you notice that the file /var/log/auth.log has been cleared. However, you find that the attacker's commands are still partially recoverable. Which artifact most likely contains the attacker's command history?

⚠ Common exam trap

The CHFI exam often tests the misconception that /var/log/syslog or /var/log/auth.log captures all user activity, but the trap here is that command history is user-specific and stored in the home directory's .bash_history file, not in system logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

~/.bash_history

The ~/.bash_history file stores the command history for individual user accounts, including commands executed by an attacker who gained shell access. Even if /var/log/auth.log is cleared, this file retains the attacker's command history unless explicitly deleted or truncated. This makes it a key artifact for recovering attacker activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /var/log/syslog

    Why it's wrong here

    /var/log/syslog records kernel, daemon, and system-level messages, but it does not capture interactive shell commands by default. While syslog can be configured to log certain events like sudo or authentication, it lacks the per-user command history of each bash session. Thus it is an unreliable source for a complete command history.

  • ✓

    ~/.bash_history

    Why this is correct

    ~/.bash_history is the correct artifact because it is the per-user history file that bash appends with every command entered interactively. When a shell exits cleanly, the session's commands are written here, making it a direct record of user activity. Investigators commonly use it to reconstruct an attacker's command sequence, though it can be disabled or truncated.

  • ✗

    /proc/1/cmdline

    Why it's wrong here

    /proc/1/cmdline is a pseudo-file that exposes the initial command line arguments of process ID 1, typically the init system like systemd or SysV init. It is a live snapshot of a single process, not a historical log of user commands. Reading it only shows how the kernel started the first process, not what users typed later.

  • ✗

    /etc/shadow

    Why it's wrong here

    /etc/shadow is a root-only-readable file that stores hashed user passwords and password aging policy, not command history. It exists to manage authentication and is protected to prevent unauthorized password hash disclosure. Its content has no bearing on what commands were executed in a shell session.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.