CHFI OS and Network Forensics Practice Question
During a Linux forensic investigation, you find that the file /var/log/auth.log has been deleted. Which of the following artefacts would BEST help determine recent SSH login attempts?
⚠ Common exam trap
Candidates often assume auth.log is the only source for SSH login data, overlooking the wtmp file that the 'last' command queries, which is a separate and more persistent artefact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Output of the 'last' command
The 'last' command reads the /var/log/wtmp binary log file, which records all login and logout events, including SSH sessions. Even if /var/log/auth.log is deleted, the wtmp file persists and provides a reliable record of recent SSH login attempts, making option D the best choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Contents of /etc/shadow
Why it's wrong here
The /etc/shadow file stores hashed password values and password-aging metadata (e.g., last password change date, minimum/maximum age). Its fields track password policy, not authentication events. A login attempt timestamp is not recorded there, and even the 'last password change' field reflects admin resets, not user SSH login times, so this file cannot reveal recent access.
- ✗
Bash history from /root/.bash_history
Why it's wrong here
The root user's .bash_history file contains a chronological list of commands executed in interactive shells, such as 'nano', 'ls', or 'ssh'. It does not log authentication attempts, and its content is session-specific, editable by the user, and frequently truncated or omitted in minimal installations. It cannot reliably show whether a remote login occurred, let alone failed or succeeded attempts.
- ✗
Cron job entries in /etc/crontab
Why it's wrong here
The /etc/crontab file defines scheduled job execution times for the cron daemon, specifying commands, users, and run times. It is completely unrelated to login activity: it drives background tasks like backups or log rotation. Entries in this file have no bearing on SSH connection attempts, and examining it would only reveal automation schedules, not an intruder's access.
- ✓
Output of the 'last' command
Why this is correct
The 'last' command parses the binary wtmp log (/var/log/wtmp) to display session records, including user, terminal, source IP, and login/logout timestamps. This directly captures successful local and SSH logins, making it the standard artifact for identifying recent successful authentication events. Concatenating the output with the 'last' command's default format provides a timeline of who accessed the system.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.