CHFI OS and Network Forensics Practice Question
Which Linux log file is the primary source for authentication-related events, including SSH login attempts and sudo usage?
⚠ Common exam trap
The CHFI exam often tests the distinction between distribution-specific log files, so the trap here is that candidates familiar with Red Hat-based systems (where /var/log/secure is the auth log) may incorrectly choose /var/log/messages or /var/log/syslog, not realizing that CHFI focuses on Debian/Ubuntu conventions where /var/log/auth.log is the standard.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/var/log/auth.log
/var/log/auth.log is the dedicated Linux log file for authentication-related events, including SSH login attempts (via PAM and sshd), sudo usage, and user authentication failures. This file is managed by the syslog daemon and is the primary source for forensic analysis of authentication activity on Debian-based systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/var/log/kern.log
Why it's wrong here
This file records kernel-level messages generated by the Linux kernel, including hardware errors, driver initialization, and kernel panic traces. Authentication events occur at a higher layer—such as PAM in userspace or login programs—so they are written to auth.log, not to the kernel log. Although security-related kernel messages like IMA or AppArmor denials may appear, they do not represent user authentication events.
- ✗
/var/log/syslog
Why it's wrong here
/var/log/syslog is the default catch-all log for system-wide messages from daemons and services, typically excluding auth-related facilities. In rsyslog configurations, the auth and authpriv facilities are explicitly directed to /var/log/auth.log, so syslog should not be considered the authoritative source for authentication records. While a syslog line might mention an application-level authentication failure, this log is neither dedicated nor consistent enough for forensic authentication analysis.
- ✓
/var/log/auth.log
Why this is correct
This is the primary authentication log on Debian-based Linux distributions, recording events from the auth and authpriv syslog facilities. It captures successful and failed logins, sudo usage, SSH public-key and password authentication, user account changes, cron jobs run with authentication, and PAM module activity. As the central repository for authentication-related messages, forensic examiners look here first for evidence of unauthorized access or identity-related events.
- ✗
/var/log/messages
Why it's wrong here
/var/log/messages is a general-purpose system log common on Red Hat-based distributions, containing boot messages, kernel messages, and various daemon notices. It typically lacks authentication entries because authpriv messages are routed to /var/log/secure instead, or to auth.log on other systems. Even when auth lines appear, the log's broad scope means authentication events are not guaranteed to be present or complete, making it unreliable as the primary source.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.