Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI Bash history Practice Question

During a forensic investigation of a Linux system, you need to determine which commands a user executed in their shell session. Which file would you examine to find this information?

⚠ Common exam trap

It's easy for candidates to confuse /var/log/auth.log (which logs authentication events) with command history, but auth.log does not capture the actual commands typed in a shell.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/home/username/.bash_history

The .bash_history file in a user's home directory stores the command history for that user's interactive Bash shell sessions. By default, Bash appends each command to this file when the session ends, making it the primary source for reconstructing a user's executed commands during forensic analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /var/log/auth.log

    Why it's wrong here

    The /var/log/auth.log file is the canonical Debian/Ubuntu log for authentication-related events, recording successful and failed login attempts, SSH public-key validations, and sudo privilege elevation requests. While an account may appear here when it authenticates, this log is not designed to capture the interactive command lines the user typed after login. Shell commands are not emitted to auth.log unless a custom auditing tool or PAM session hook has been explicitly configured to forward them, so this file is not a reliable source for command history.

  • ✗

    /etc/passwd

    Why it's wrong here

    /etc/passwd is a world-readable plain-text database that defines local user accounts, mapping each username to a numeric UID/GID, the canonical home directory path, and the login shell to spawn. It also contains placeholder fields such as the encrypted password marker (x), but it has no mechanism whatsoever for storing a user's typed commands or shell session activity. Investigators may use it to identify which home directory to inspect, but its contents are static account metadata, not an audit trail of interactive terminal operations.

  • ✗

    /var/log/syslog

    Why it's wrong here

    /var/log/syslog aggregates general operating system messages from the kernel, systemd/journald, and many userspace daemons, capturing events such as service starts, networking messages, and hardware probes. Although applications may call syslog(3) to record their own actions, an interactive bash shell does not routinely write each executed command to syslog, so command history is absent from this file by default. A forensic examiner might find references to a process after it ran, but the actual command-line input from a normal user session is not archived there unless auditd or a similar subsystem has been deployed to log execve() calls.

  • ✓

    /home/username/.bash_history

    Why this is correct

    .bash_history is the default per-user history file in the home directory of a user running the GNU Bash shell; it records commands interactively typed at the shell's prompt, appended in plain text, and can be read with the 'history' builtin. Each line is one command, and the order generally reflects the order of execution, though Bash does not by default store a timestamp unless HISTTIMEFORMAT is configured. For a forensic investigation this file is the most direct source of a user's command activity, but a sophisticated user can clear or edit the file, and commands running non-interactively or in subshells may not be captured.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.