GCIH Incident Response and Cyber Investigation Practice Question
During an investigation of a compromised Linux web server, an incident responder needs to identify which user account was used to establish an outbound SSH session to an external IP address. Which artifact should the responder examine first?
⚠ Common exam trap
The trap here is assuming shell history or process listings reliably attribute network connections to a user account, when only the authentication log records the SSH session owner.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The system authentication log, such as /var/log/auth.log or /var/log/secure
SSH session events are logged by the sshd daemon to the system authentication log, which includes the account name and connection endpoints. Examining /var/log/auth.log on Debian-based systems or /var/log/secure on Red Hat-based systems gives the responder the user attribution and timing needed. Other artifacts lack the necessary account-to-connection correlation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The system's cron job definitions under /etc/cron.d
Why it's wrong here
Cron definitions show scheduled tasks and the accounts that run them, but they do not log interactive or scripted SSH sessions that are not scheduled. An attacker's outbound SSH session is unlikely to appear in cron unless it was deliberately scheduled. This makes cron a poor primary source for attributing a live SSH connection to a user.
- ✗
The bash command history file for each user under /home
Why it's wrong here
Bash history records commands typed interactively by users, but it does not reliably capture the source user of a network connection and can be disabled, truncated, or modified by an attacker. It also excludes non-interactive sessions. For attributing an outbound SSH connection to a specific account, the authentication and session logs are far more authoritative than shell history.
- ✗
The kernel ring buffer output from the dmesg command
Why it's wrong here
The kernel ring buffer contains hardware, driver, and boot messages. It does not normally record user-level SSH session details or account names. While it may show network interface events, it cannot attribute an outbound SSH connection to a user account. dmesg is the wrong data source for authentication attribution.
- ✓
The system authentication log, such as /var/log/auth.log or /var/log/secure
Why this is correct
The authentication log records SSH session events, including the user account and the source and destination of connections. On most Linux distributions, sshd writes session open and close entries with the username and remote address, allowing the responder to correlate the outbound connection to a specific account. This directly answers which user initiated the session.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.