Courseiva
OS and Network Forensics →easyMultiple Select

CHFI OS and Network Forensics Practice Question

Which TWO of the following are common Linux log files that can be used for forensic analysis?

⚠ Common exam trap

The exam highly tests the distinction between configuration files (like /etc/passwd and /etc/shadow) and dynamic log files, leading candidates to mistakenly select static system files as sources of forensic evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/var/log/syslog

/var/log/syslog (B) is correct because it is the standard system log on many Linux distributions (Debian/Ubuntu and others), recording kernel messages, daemon activity, service events, and general system errors that are valuable for reconstructing a timeline during forensic analysis. /var/log/auth.log (C) is also correct because it captures authentication-related events such as logins, sudo usage, su attempts, and PAM/SSH authentication failures or successes, which are essential for investigating unauthorized access. The unmarked options do not belong: /etc/passwd (A) and /etc/shadow (D) are account database files, not log files, even though they are useful for reviewing user accounts and password hashes, and /proc/cpuinfo (E) is a virtual file exposing CPU details, not a log of system or security events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /etc/passwd

    Why it's wrong here

    /etc/passwd is a colon-delimited user account database that stores usernames, UIDs, GIDs, home directories, shell paths, and, historically, hashed passwords before they were moved to /etc/shadow. It is a static configuration file consumed by the Name Service Switch (NSS) at login, not a time-ordered record of events. Its contents reflect current account state, not historical activity, and it is world-readable, which would be inappropriate for a security log.

  • ✓

    /var/log/syslog

    Why this is correct

    /var/log/syslog is the primary, centralized system log on Debian-based distributions like Ubuntu, written by the rsyslog daemon. It aggregates high-level kernel messages, service start and stop events, hardware errors, cron activity, and other system-level notifications from software that uses the syslog(3) API. This file is essential for troubleshooting and forensic timeline reconstruction because it captures a broad chronological record of system behavior, though it deliberately excludes authentication events.

  • ✓

    /var/log/auth.log

    Why this is correct

    /var/log/auth.log is the dedicated authentication log on Debian-based systems, also written by rsyslog but filtered to the auth and authpriv facilities. It records both successful and failed login attempts, sudo and su invocations, SSH key and password authentications, and user account changes, making it indispensable for detecting brute-force attacks, credential misuse, and privilege escalation. Unlike the general syslog, this file is restricted to security-relevant authentication activity, enabling a focused audit trail.

  • ✗

    /etc/shadow

    Why it's wrong here

    /etc/shadow is a privilege-restricted file containing encrypted password hashes, password aging parameters, and account expiration flags for each user. It is a current-state security database read by PAM at authentication time; it never records events, timestamps, or access histories, so it cannot serve as a log. Its fields, like the last-changed epoch date, are configuration attributes, not an audit trail, and the file is intentionally unreadable by normal users.

  • ✗

    /proc/cpuinfo

    Why it's wrong here

    /proc/cpuinfo is a virtual file exposed by the procfs filesystem, dynamically populated by the kernel to display live CPU specifications such as vendor, model, clock speed, cache size, and feature flags. It is not a persistent file on disk—it exists only in memory and changes with kernel state, with no historical entries or event records. Treating it as a log would confuse static snapshot data with time-series activity logs; logs are append-only files preserving past events, whereas /proc files are ephemeral views of the present.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.